DVA-C02 Troubleshooting and Optimization Practice Question
Network Topology
Refer to the exhibit. A CloudFormation stack creation failed. What is the most likely cause of the failure?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The IAM role's trust policy does not allow Lambda to assume the role.
The IAM role's trust policy does not allow Lambda to assume the role. In CloudFormation, when a stack provisions a Lambda function with an execution role, the role's trust policy must include lambda.amazonaws.com as a principal with sts:AssumeRole; if that trust relationship is missing or misconfigured, role assumption fails and the stack creation fails. Option B is unlikely because Lambda function names only need to be unique within an account and Region, and CloudFormation would typically surface a naming conflict differently. Option C is not the most likely cause because a code syntax error usually causes invocation failures after deployment, not stack creation failure. Option D would cause runtime logging failures, but the role could still be assumed and the function created, so it would not typically fail the stack at creation time.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The IAM role's trust policy does not allow Lambda to assume the role.
Why this is correct
The trust policy of an IAM role specifies which entities are allowed to assume that role. For a Lambda function to successfully execute, its associated execution role must have a trust policy that explicitly lists 'lambda.amazonaws.com' as a principal. If this service principal is missing or incorrectly configured, the AWS Lambda service cannot assume the role, leading to a CloudFormation stack creation failure as the function cannot be properly provisioned.
- ✗
The Lambda function name conflicts with an existing function.
Why it's wrong here
A Lambda function name conflict typically results in a 'ResourceConflictException' or similar error message from CloudFormation, explicitly indicating that a resource with the specified name already exists. The error described in the correct answer, however, points to an issue with the IAM role's trust policy, which is distinct from a naming collision. CloudFormation would provide a much clearer and different error if the function name were the problem.
- ✗
The Lambda function code has a syntax error.
Why it's wrong here
Syntax errors in Lambda function code are generally detected during the function's execution, not during its initial creation via CloudFormation. CloudFormation validates the template structure and resource properties, but it does not execute or parse the runtime code itself during stack provisioning. An error related to an IAM role's trust policy during stack creation clearly indicates a configuration problem external to the function's internal logic.
- ✗
The Lambda execution role does not have the required permissions to write to CloudWatch Logs.
Why it's wrong here
The inability to write to CloudWatch Logs due to insufficient permissions would manifest as execution errors *after* the Lambda function has been successfully created and invoked. This is a permissions policy issue, distinct from a trust policy problem. The error in question specifically prevents the Lambda service from *assuming* the role in the first place, which is a fundamental trust policy misconfiguration that blocks resource creation.
Visual reference
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.