Courseiva

SAP-C02 Continuous Improvement for Existing Solutions Practice Question

Network Topology
$ aws logs describe-log-groupsquery 'logGroups[?starts_with(logGroupName,`/aws/lambda/`)]'Refer to the exhibit.Output:"logGroupName": "/aws/lambda/MyFunction","creationTime": 1609459200000,"metricFilterCount": 0,"arn": "arn:aws:logs:us-east-1:123456789012:log-group:/aws/lambda/MyFunction:*","storedBytes": 0,"retentionInDays": 7

A developer notices that CloudWatch Logs for a Lambda function show no logs after a recent deployment. The function is invoked successfully. What is the most likely cause?

⚠ Common exam trap

The trap is assuming that a successful invocation implies logging works; candidates forget that logging is a separate IAM-authorized API call that can fail independently of the function's business logic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The Lambda execution role does not have permissions to write to CloudWatch Logs.

Lambda writes logs to CloudWatch Logs using the function's execution role. If that role lacks logs:CreateLogGroup, logs:CreateLogStream, and logs:PutLogEvents permissions, invocations succeed but no log events appear. This is the most common cause of silent logging after a deployment that changed IAM roles.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The Lambda function is exceeding the CloudWatch Logs API rate limits.

    Why it's wrong here

    CloudWatch Logs throttling would produce partial or delayed log entries, not complete absence after deployment. It tempts because rate limits are a known Lambda concern, but the scenario's total silence points to the execution role lacking logs:CreateLogStream and logs:PutLogEvents permissions.

  • ✓

    The Lambda execution role does not have permissions to write to CloudWatch Logs.

    Why this is correct

    Lambda writes logs to CloudWatch Logs using its execution role's permissions. If that role lacks logs:CreateLogStream and logs:PutLogEvents, invocations succeed but emit nothing. This directly explains the stem's constraint: successful invocations with no log output after deployment.

  • ✗

    The log group retention policy is set to 7 days, which expired old logs.

    Why it's wrong here

    Retention expiry deletes logs older than seven days, but a recent deployment's logs would still be present, so this cannot explain their absence. Retention policies are configured deliberately to control storage cost and compliance, and would be the answer if logs from weeks ago had vanished while recent ones remained.

  • ✗

    The log group was deleted and not recreated.

    Why it's wrong here

    Lambda recreates a missing log group automatically on the next invocation, so deletion would not persist as absent logs. It tempts because deletion sounds plausible, but the actual cause is a missing or altered execution role permission for logs:CreateLogStream and logs:PutLogEvents.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

One of 984 original SAP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.