SAP-C02 Continuous Improvement for Existing Solutions Practice Question
Exhibit
Refer to the exhibit.
Resources:
MyBucket:
Type: AWS::S3::Bucket
Properties:
BucketName: my-unique-bucket-name
VersioningConfiguration:
Status: Enabled
MyLambdaFunction:
Type: AWS::Lambda::Function
Properties:
Handler: index.handler
Role: !GetAtt LambdaExecutionRole.Arn
Code:
ZipFile: |
const AWS = require('aws-sdk');
exports.handler = async (event) => {
console.log('Processing event:', JSON.stringify(event));
return 'Success';
};
Runtime: nodejs14.x
LambdaExecutionRole:
Type: AWS::IAM::Role
Properties:
AssumeRolePolicyDocument:
Version: '2012-10-17'
Statement:
- Effect: Allow
Principal:
Service: lambda.amazonaws.com
Action: sts:AssumeRole
Policies:
- PolicyName: LambdaPolicy
PolicyDocument:
Version: '2012-10-17'
Statement:
- Effect: Allow
Action: logs:CreateLogGroup
Resource: arn:aws:logs:*:*:*
- Effect: Allow
Action:
- logs:CreateLogStream
- logs:PutLogEvents
Resource: arn:aws:logs:*:*:*
BucketNotification:
Type: AWS::S3::BucketNotification
DependsOn: MyLambdaFunction
Properties:
Bucket: !Ref MyBucket
NotificationConfiguration:
LambdaFunctionConfigurations:
- LambdaFunctionArn: !GetAtt MyLambdaFunction.Arn
Events:
- s3:ObjectCreated:*A solutions architect deployed the above CloudFormation template. However, the Lambda function is not triggered when objects are uploaded to the S3 bucket. What is the most likely cause?
⚠ Common exam trap
SAP-C02 often tests the confusion between the Lambda execution role (what the function can access) and the Lambda resource-based policy (who can invoke the function) — candidates pick the execution role fix when the real issue is the missing invoke permission.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The Lambda function lacks a resource-based policy that allows S3 to invoke it.
For S3 to invoke a Lambda function, the function must have a resource-based policy (permission) that grants the s3.amazonaws.com service principal permission to call lambda:InvokeFunction. Without this permission, S3's notification configuration is accepted but invocation fails silently. This is the most common cause of 'Lambda not triggered' in CloudFormation deployments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The BucketNotification resource depends on MyLambdaFunction, but the notification configuration is incorrect.
Why it's wrong here
The template's notification configuration is a red herring; the failure stems from the missing AWS::Lambda::Permission resource granting S3 invoke rights. Without that permission S3 cannot call the function. A notification configuration error would be the cause only if the resource properties themselves were malformed.
- ✓
The Lambda function lacks a resource-based policy that allows S3 to invoke it.
Why this is correct
S3 invokes Lambda asynchronously, which requires a resource-based policy granting s3.amazonaws.com permission to call InvokeFunction. Without this policy, uploads succeed silently but no invocation occurs, so the function never triggers despite any execution role permissions.
- ✗
The Lambda execution role does not have permission to access S3.
Why it's wrong here
Execution-role permissions govern what the function does after invocation, not whether S3 can invoke it. The missing AWS::Lambda::Permission resource is what blocks the trigger. An execution-role gap would be the cause only if the function ran but its own S3 API calls returned AccessDenied.
- ✗
The Lambda function code does not read the S3 object content.
Why it's wrong here
Whether the function reads object content is irrelevant: the trigger never invokes it, so no code executes. The function code would be the cause only if invocations occurred but processing failed. Here the missing AWS::Lambda::Permission resource prevents S3 from invoking the function at all.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 984 original SAP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.