DVA-C02 Deployment Practice Question
Exhibit
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"s3:PutObject",
"s3:GetObject",
"s3:DeleteObject"
],
"Resource": "arn:aws:s3:::my-bucket/*"
},
{
"Effect": "Allow",
"Action": [
"lambda:InvokeFunction"
],
"Resource": "*"
}
]
}Refer to the exhibit. An IAM policy is attached to a user who needs to deploy a serverless application. The user reports that they cannot upload a new version of a Lambda function using the AWS CLI. What is the MOST likely reason?
⚠ Common exam trap
Candidates often assume the error is due to S3 permissions (Option C) because they think Lambda code must be uploaded from S3, but the CLI can upload directly from a local file, and the real missing permission is `lambda:UpdateFunctionCode`.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The policy does not include lambda:UpdateFunctionCode.
The error occurs because the IAM policy attached to the user does not include the `lambda:UpdateFunctionCode` permission, which is required to upload a new version of a Lambda function via the AWS CLI. Without this action, the `update-function-code` command fails, even if other Lambda permissions like `lambda:InvokeFunction` are present. The policy must explicitly allow `lambda:UpdateFunctionCode` to enable code updates.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The Lambda invoke permission is scoped to a specific function.
Why it's wrong here
The `Resource` element in an IAM policy explicitly defines the scope of the `Action`. When `Resource` is set to `*` for `lambda:InvokeFunction`, it explicitly grants permission to invoke *any* Lambda function within the AWS account, not just a single, specific one. Therefore, the statement claiming the permission is scoped to a specific function is incorrect, as the wildcard denotes broad access for this action.
- ✓
The policy does not include lambda:UpdateFunctionCode.
Why this is correct
To modify the deployment package or code of an existing AWS Lambda function, an IAM principal requires the `lambda:UpdateFunctionCode` action to be explicitly allowed in their attached policy. Since the provided policy document does not list `lambda:UpdateFunctionCode` among its allowed actions, the user lacks the necessary permission to perform this specific administrative operation. This correctly identifies a missing capability for code updates.
- ✗
The user does not have permission to write to the S3 bucket.
Why it's wrong here
The `s3:PutObject` action within an IAM policy grants the principal the explicit permission to upload new objects to an Amazon S3 bucket or overwrite existing ones. If this action is present and allowed, as indicated in the policy, the user possesses the capability to write data into the specified S3 bucket. Consequently, the statement asserting the user lacks permission to write to S3 is factually incorrect.
- ✗
The user is not in the same AWS region as the Lambda function.
Why it's wrong here
AWS Identity and Access Management (IAM) policies are global constructs that define permissions across all AWS regions by default, unless a specific region is explicitly constrained within a `Condition` block. The physical region where a user initiates a request or where a resource resides does not inherently restrict the permissions granted by an IAM policy. Therefore, the user's region being different from the Lambda function's region is not a factor in determining permission, making this statement incorrect.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
This DVA-C02 question is part of Courseiva's 1,135-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.