Courseiva

SAP-C02 Continuous Improvement for Existing Solutions Practice Question

Exhibit

Refer to the exhibit.

Resources:
  MyBucket:
    Type: AWS::S3::Bucket
    Properties:
      BucketName: my-unique-bucket-name
      VersioningConfiguration:
        Status: Enabled
  MyLambdaFunction:
    Type: AWS::Lambda::Function
    Properties:
      Handler: index.handler
      Role: !GetAtt LambdaExecutionRole.Arn
      Code:
        ZipFile: |
          const AWS = require('aws-sdk');
          exports.handler = async (event) => {
            console.log('Processing event:', JSON.stringify(event));
            return 'Success';
          };
      Runtime: nodejs14.x
  LambdaExecutionRole:
    Type: AWS::IAM::Role
    Properties:
      AssumeRolePolicyDocument:
        Version: '2012-10-17'
        Statement:
          - Effect: Allow
            Principal:
              Service: lambda.amazonaws.com
            Action: sts:AssumeRole
      Policies:
        - PolicyName: LambdaPolicy
          PolicyDocument:
            Version: '2012-10-17'
            Statement:
              - Effect: Allow
                Action: logs:CreateLogGroup
                Resource: arn:aws:logs:*:*:*
              - Effect: Allow
                Action:
                  - logs:CreateLogStream
                  - logs:PutLogEvents
                Resource: arn:aws:logs:*:*:*
  BucketNotification:
    Type: AWS::S3::BucketNotification
    DependsOn: MyLambdaFunction
    Properties:
      Bucket: !Ref MyBucket
      NotificationConfiguration:
        LambdaFunctionConfigurations:
          - LambdaFunctionArn: !GetAtt MyLambdaFunction.Arn
            Events:
              - s3:ObjectCreated:*

A solutions architect deployed the above CloudFormation template. However, the Lambda function is not triggered when objects are uploaded to the S3 bucket. What is the most likely cause?

⚠ Common exam trap

SAP-C02 often tests the confusion between the Lambda execution role (what the function can access) and the Lambda resource-based policy (who can invoke the function) — candidates pick the execution role fix when the real issue is the missing invoke permission.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The Lambda function lacks a resource-based policy that allows S3 to invoke it.

For S3 to invoke a Lambda function, the function must have a resource-based policy (permission) that grants the s3.amazonaws.com service principal permission to call lambda:InvokeFunction. Without this permission, S3's notification configuration is accepted but invocation fails silently. This is the most common cause of 'Lambda not triggered' in CloudFormation deployments.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The BucketNotification resource depends on MyLambdaFunction, but the notification configuration is incorrect.

    Why it's wrong here

    The template's notification configuration is a red herring; the failure stems from the missing AWS::Lambda::Permission resource granting S3 invoke rights. Without that permission S3 cannot call the function. A notification configuration error would be the cause only if the resource properties themselves were malformed.

  • ✓

    The Lambda function lacks a resource-based policy that allows S3 to invoke it.

    Why this is correct

    S3 invokes Lambda asynchronously, which requires a resource-based policy granting s3.amazonaws.com permission to call InvokeFunction. Without this policy, uploads succeed silently but no invocation occurs, so the function never triggers despite any execution role permissions.

  • ✗

    The Lambda execution role does not have permission to access S3.

    Why it's wrong here

    Execution-role permissions govern what the function does after invocation, not whether S3 can invoke it. The missing AWS::Lambda::Permission resource is what blocks the trigger. An execution-role gap would be the cause only if the function ran but its own S3 API calls returned AccessDenied.

  • ✗

    The Lambda function code does not read the S3 object content.

    Why it's wrong here

    Whether the function reads object content is irrelevant: the trigger never invokes it, so no code executes. The function code would be the cause only if invocations occurred but processing failed. Here the missing AWS::Lambda::Permission resource prevents S3 from invoking the function at all.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 984 original SAP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.