Courseiva
Deployment →mediumMultiple Choice

DVA-C02 AWS::Lambda::Permission Practice Question

A developer is deploying a serverless application using AWS SAM. The application includes an AWS Lambda function that is triggered by an S3 bucket event when an object is created. The developer wants to ensure that the Lambda function has the correct permissions to be invoked by S3. Which resource should the developer define in the SAM template?

⚠ Common exam trap

A common mix-up: candidates confuse the Lambda execution role (IAM::Role) with the invocation permission (Lambda::Permission), or mistakenly think S3 uses a bucket policy or event source mapping to trigger Lambda, when in fact S3 uses a push-based notification that requires a resource-based policy on the Lambda function.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS::Lambda::Permission

AWS::Lambda::Permission is the correct resource because it explicitly grants the S3 service principal permission to invoke the Lambda function when an object is created. In AWS SAM, this resource is automatically generated when you define an S3 event source on a Lambda function, but if you need to declare it manually or override permissions, you use AWS::Lambda::Permission with a SourceArn pointing to the S3 bucket and a SourceAccount to prevent confused deputy attacks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    AWS::Lambda::Permission

    Why this is correct

    AWS::Lambda::Permission creates the resource-based policy granting S3 the lambda:InvokeFunction action, which is what allows the bucket's event notification to invoke the function. Execution roles govern outbound calls, not inbound invocation, so this resource satisfies the stated requirement.

  • ✗

    AWS::S3::BucketPolicy

    Why it's wrong here

    A bucket policy controls access to the S3 bucket itself, not the permissions for S3 to invoke Lambda.

  • ✗

    AWS::Lambda::EventSourceMapping

    Why it's wrong here

    EventSourceMapping resources support stream and queue sources such as Kinesis, DynamoDB Streams and SQS, not S3 bucket notifications. S3 invokes Lambda through bucket notification configuration plus a resource-based permission. Event source mappings would be right for polled stream consumption, where Lambda reads records rather than being pushed to.

  • ✗

    AWS::IAM::Role

    Why it's wrong here

    An IAM role supplies the function's execution permissions for AWS services it calls, not the permission allowing S3 to invoke it. Invocation is granted by a Lambda resource-based policy. IAM roles are the right choice when the function itself must access other services, such as reading DynamoDB or writing to CloudWatch.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every DVA-C02 question from scratch — 1,135 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.