Courseiva

SCS-C02 Least Privilege Practice Question

A developer needs to allow a Lambda function to write logs to CloudWatch Logs. What is the MINIMUM IAM policy that should be attached to the Lambda execution role?

⚠ Common exam trap

SCS-C02 often tests whether candidates know that Lambda requires CreateLogGroup and CreateLogStream in addition to PutLogEvents — many pick only PutLogEvents and miss the creation actions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

{"Effect":"Allow","Action":["logs:CreateLogGroup","logs:CreateLogStream","logs:PutLogEvents"],"Resource":"*"}

The minimum policy for a Lambda function to write logs to CloudWatch Logs must include logs:CreateLogGroup, logs:CreateLogStream, and logs:PutLogEvents. Lambda creates the log group and stream on first invocation, so all three actions are required. Resource '*' is acceptable because the log group name is not known in advance and Lambda needs to create it dynamically.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    {"Effect":"Allow","Action":["logs:CreateLogGroup","logs:CreateLogStream","logs:PutLogEvents"],"Resource":"*"}

    Why this is correct

    CloudWatch Logs requires exactly these three log actions for a Lambda function to create its log group, stream and write events. Omitting any action causes logging to fail, so this is the minimum viable set.

  • ✗

    {"Effect":"Allow","Action":"logs:PutLogEvents","Resource":"arn:aws:logs:us-east-1:123456789012:log-group:my-log-group:*"}

    Why it's wrong here

    PutLogEvents alone cannot create the log group or stream on first invocation, so the function fails unless both already exist. It is tempting because it is tightly scoped to the single write action, and would be the minimum for a Lambda writing to a pre-created log group and stream.

  • ✗

    {"Effect":"Allow","Action":"logs:*","Resource":"*"}

    Why it's wrong here

    Wildcarding logs:* on Resource:* grants far more than writing log events, including deleting log groups and streams, so it exceeds the minimum. It is tempting because it guarantees the function works without scoping errors, and would suit a broad administrative role rather than a least-privilege execution role.

  • ✗

    {"Effect":"Allow","Action":["logs:DescribeLogGroups","logs:DescribeLogStreams"],"Resource":"*"}

    Why it's wrong here

    DescribeLogGroups and DescribeLogStreams are read-only metadata actions; they do not permit writing log events, so the function still cannot emit logs. It is tempting because these actions are commonly bundled alongside PutLogEvents in managed policies, and would be correct for a role that only lists existing log groups.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on SCS-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company wants to allow a Lambda function to read messages from an SQS queue and write logs to CloudWatch Logs. Which TWO IAM actions should be included in the Lambda execution role?

easy
  • A.logs:DeleteLogGroup
  • ✓ B.sqs:ReceiveMessage
  • C.cloudwatch:*
  • ✓ D.logs:CreateLogStream and logs:PutLogEvents
  • E.sqs:SendMessage

Why B: Options B and D are correct because they provide the specific actions needed: sqs:ReceiveMessage to read from SQS and logs:CreateLogStream and logs:PutLogEvents to write logs to CloudWatch Logs. Option A (logs:DeleteLogGroup) is not required for writing logs. Option C (cloudwatch:*) is overly broad and CloudWatch Logs actions are under the logs: prefix, not cloudwatch:* which covers other CloudWatch services. Option E (sqs:SendMessage) is for sending messages, not reading.

Variation 2. A security engineer is designing a solution to allow a Lambda function to write logs to CloudWatch Logs. Which TWO actions are required in the IAM execution role? (Choose TWO.)

medium
  • A.logs:GetLogEvents
  • ✓ B.logs:PutLogEvents
  • C.logs:CreateLogStream
  • D.logs:PutRetentionPolicy
  • ✓ E.logs:CreateLogGroup

Why B: The correct options are B and E. To allow a Lambda function to write logs to CloudWatch Logs, the IAM execution role must include permissions to create a log group (logs:CreateLogGroup) if it does not already exist and to put log events (logs:PutLogEvents). While logs:CreateLogStream is also typically required, the question asks for TWO actions, and of the given options, B and E are the necessary ones. Option A (logs:GetLogEvents) is for reading logs, C (logs:CreateLogStream) is also needed but not listed as a correct choice in this two-answer scenario, and D (logs:PutRetentionPolicy) configures retention, not writing.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.