Courseiva
Security →easyMultiple Choice

DVA-C02 Security Practice Question

Exhibit

Refer to the exhibit.
CloudFormation template snippet:
Resources:
  MyLambdaFunction:
    Type: AWS::Lambda::Function
    Properties:
      Code:
        S3Bucket: my-code-bucket
        S3Key: my-function.zip
      Role: arn:aws:iam::123456789012:role/LambdaExecutionRole
      Runtime: python3.9
      Handler: index.handler

What is required for the Lambda function to access the code in the S3 bucket?

⚠ Common exam trap

Candidates often confuse the permissions needed by the IAM identity creating/updating the Lambda function (which needs access to the deployment package in S3) with the permissions needed by the Lambda execution role itself (which needs access to resources the function interacts with at runtime).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The Lambda execution role must have s3:GetObject permission on the S3 bucket.

To allow a Lambda function to access AWS resources like an S3 bucket during its execution, it must assume an IAM execution role with the appropriate permissions. To read an object from S3, the execution role must have the `s3:GetObject` permission for the target bucket and object path.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The S3 bucket policy must grant access to the Lambda service.

    Why it's wrong here

    While S3 bucket policies can grant permissions, they typically grant access to specific IAM principals (users, roles) or AWS services. For a Lambda function to access its deployment package in S3, the permissions are primarily managed through the Lambda function's execution role. The bucket policy would only be necessary if the bucket owner and the Lambda function's account were different, or if the execution role itself was explicitly denied by the bucket policy. Granting access to the "Lambda service" broadly is not the standard or most granular way to secure access for a specific function.

  • ✗

    The Lambda function must be in a VPC with an S3 VPC endpoint.

    Why it's wrong here

    Lambda functions, by default, run in an AWS-managed execution environment that has direct access to public AWS services like S3 over the internet, without requiring a VPC configuration. Placing a Lambda function within a VPC is only necessary when it needs to access private resources within that VPC, such as an RDS database or an EC2 instance. Even then, S3 access from a VPC-enabled Lambda function can occur via a NAT Gateway or a VPC endpoint, but the VPC itself is not a prerequisite for S3 interaction.

  • ✗

    The S3 bucket must be configured as a static website with CloudFront.

    Why it's wrong here

    Configuring an S3 bucket for static website hosting and integrating it with CloudFront is a setup designed for serving public web content efficiently, typically HTML, CSS, JavaScript, and images. This configuration is entirely unrelated to how an AWS Lambda function retrieves its deployment package code from an S3 bucket. Lambda accesses the S3 object directly via the S3 API, not through HTTP requests to a website endpoint or a content delivery network.

  • ✓

    The Lambda execution role must have s3:GetObject permission on the S3 bucket.

    Why this is correct

    For an AWS Lambda function to successfully retrieve its deployment package, which is stored as an object in an S3 bucket, the function's associated IAM execution role must possess the necessary permissions. Specifically, the s3:GetObject action is required to allow the Lambda service, acting on behalf of the function, to read the code object from the specified S3 bucket. Without this explicit permission, the Lambda service cannot access the code to initialize and execute the function.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every DVA-C02 question from scratch — 1,135 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.