Courseiva

DVA-C02 Troubleshooting and Optimization Practice Question

Network Topology
$ aws logs describe-log-groupslog-group-name-prefix /aws/lambda/my-functionRefer to the exhibit."logGroups": ["logGroupName": "/aws/lambda/my-function","creationTime": 1620000000000,"metricFilterCount": 0,"arn": "arn:aws:logs:us-east-1:123456789012:log-group:/aws/lambda/my-function:*","storedBytes": 0,"retentionInDays": 7

A developer notices that the Lambda function 'my-function' is not generating any logs in CloudWatch, although the function is invoked successfully. The developer runs the command above. What is the MOST likely cause?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The Lambda function's execution role is missing the 'logs:CreateLogStream' and 'logs:PutLogEvents' permissions.

The log group exists but has 0 stored bytes, meaning no log streams have been created. This typically indicates that the Lambda function's execution role does not have permissions to create log streams and put log events. The function runs but fails silently to write logs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The log group retention policy is set to 0 days.

    Why it's wrong here

    Setting a CloudWatch Logs retention policy to 0 days is not a valid configuration within AWS. Instead of immediately deleting logs, CloudWatch interprets a 0-day retention as 'never expire,' meaning logs would persist indefinitely. Therefore, if the Lambda function were successfully generating logs, they would still be visible in the log group, contradicting the observation of no logs.

  • ✗

    The Lambda function is configured to log to a custom log group.

    Why it's wrong here

    Even if a Lambda function is configured to use a custom log group, such as by setting the AWS_LAMBDA_LOG_GROUP_NAME environment variable, logs would still be directed and written to that specified group. The problem statement indicates *no logs at all* are appearing, not that logs are missing from the *default* log group. A custom log group configuration would simply change the destination, not prevent logging entirely if permissions were correct.

  • ✗

    The Lambda function has reserved concurrency set to 0.

    Why it's wrong here

    Setting a Lambda function's reserved concurrency to 0 explicitly prevents the function from being invoked by any triggers. This means the function's code would not execute, and consequently, no logs would be generated because the runtime environment is never spun up. The issue would manifest as failed invocations or throttled requests, rather than successful invocations that simply fail to produce logs.

  • ✓

    The Lambda function's execution role is missing the 'logs:CreateLogStream' and 'logs:PutLogEvents' permissions.

    Why this is correct

    The Lambda function's execution role requires specific permissions to interact with CloudWatch Logs. The 'logs:CreateLogStream' permission allows the function to create a unique log stream for its execution environment within the designated log group, while 'logs:PutLogEvents' is essential for sending the actual log data to that stream. Without both of these critical permissions, the function cannot successfully publish any output or runtime messages to CloudWatch Logs, leading to the observation of no logs.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

Courseiva writes every DVA-C02 question from scratch — 1,135 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.