DVA-C02 Security Practice Question
Network Topology
Refer to the exhibit. A developer created an IAM role for a Lambda function. When the Lambda function invokes, it fails with an access denied error when trying to write logs to CloudWatch Logs. What is the most likely cause?
⚠ Common exam trap
Candidates often confuse trust policies with permissions policies, assuming that if the role is assumed successfully, all subsequent API calls will work. However, the trust policy only governs role assumption, not the actions the role can perform.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The role lacks a permissions policy that allows CloudWatch Logs actions.
The Lambda function's IAM role must include a permissions policy that grants the `logs:CreateLogGroup`, `logs:CreateLogStream`, and `logs:PutLogEvents` actions. Without these permissions, the Lambda runtime cannot write logs to CloudWatch Logs, resulting in an access denied error. The error occurs at invocation time when the Lambda service attempts to create or write to the log stream on behalf of the function.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The trust policy does not allow the Lambda service to assume the role.
Why it's wrong here
The trust policy defines which principals are allowed to assume the IAM role. If the Lambda service (specifically 'lambda.amazonaws.com') were not permitted to assume the role, the Lambda function would fail immediately upon invocation, unable to acquire temporary credentials to interact with any AWS service. Since the function is presumably executing and encountering issues with logging, it implies the role assumption was successful, making the trust policy valid for the Lambda service.
- ✗
The CloudWatch Logs log group has a resource-based policy that denies the Lambda function.
Why it's wrong here
CloudWatch Logs log groups typically do not require resource-based policies for services like Lambda to write logs. Instead, the permissions for a Lambda function to create log groups, create log streams, and put log events are granted via an identity-based permissions policy attached directly to the Lambda execution role. A resource-based policy on the log group itself would be highly unusual for this scenario and is not the standard mechanism for granting write access from an AWS service.
- ✓
The role lacks a permissions policy that allows CloudWatch Logs actions.
Why this is correct
The permissions policy attached to an IAM role dictates the specific AWS API actions that the role, once assumed, is authorized to perform. For a Lambda function to successfully send logs to CloudWatch, its execution role must have a permissions policy explicitly allowing actions such as 'logs:CreateLogGroup', 'logs:CreateLogStream', and 'logs:PutLogEvents'. Without these explicit permissions, the function's attempts to interact with CloudWatch Logs will result in an "Access Denied" error, even if the role itself was successfully assumed.
- ✗
The Lambda function is not associated with this role.
Why it's wrong here
Every AWS Lambda function must be associated with an IAM execution role, which it assumes to obtain temporary credentials for interacting with other AWS services. If the Lambda function were not associated with any role, or the incorrect role, it would fail to invoke or execute any code that attempts AWS API calls, resulting in immediate permission errors. The scenario implies the function is running but failing at a specific task (logging), indicating that a role is associated and assumed, but its permissions are insufficient.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.