Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

Network Topology
$ aws logs describe-log-groupslog-group-name-prefix /aws/lambda/my-function$ aws lambda invokefunction-name my-functionpayload '{}' output.txt$ aws logs describe-log-streamslog-group-name /aws/lambda/my-function"logGroups": []"StatusCode": 200,"ExecutedVersion": "$LATEST""logGroups": ["logGroupName": "/aws/lambda/my-function","creationTime": 1620000000000,"retentionInDays": 14,"metricFilterCount": 0,"arn": "arn:aws:logs:us-east-1:123456789012:log-group:/aws/lambda/my-function:*","storedBytes": 1024,"logGroupClass": "STANDARD""logStreams": []

Refer to the exhibit. After invoking the Lambda function, why are there no log streams in the log group?

⚠ Common exam trap

SCS-C02 often tests the misconception that Lambda needs a pre-created log group or that timeouts/retention settings suppress log delivery, when the real culprit in an empty log group is almost always missing CloudWatch Logs permissions on the execution role.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The Lambda function's execution role lacks permissions to write to CloudWatch Logs.

Lambda writes logs to CloudWatch Logs using the permissions granted to its execution role. If that role lacks the required actions (logs:CreateLogGroup, logs:CreateLogStream, logs:PutLogEvents), the function still executes but the log writes are silently denied, so no log streams appear in the log group. This is the classic cause of an empty log group after a successful invocation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The CloudWatch Logs log group retention policy is set to 0 days.

    Why it's wrong here

    A CloudWatch Logs retention policy controls how long log events are retained after they are written, not whether a log group or log stream is created. The value 0 days is not a valid retention period in AWS (minimum is 1 day), and even an immediate-expiration policy would only delete events that already exist. Since no log streams are present at all, the problem occurs before any log event is written, which is unrelated to retention.

  • ✗

    The Lambda function is not configured with a CloudWatch Logs log group.

    Why it's wrong here

    The exhibit explicitly shows a log group in the describe-log-groups output that matches the Lambda function's expected name, such as /aws/lambda/your-function-name. Lambda automatically uses this convention, and the log group's existence confirms that the function is associated with it, either from automatic creation during an earlier invocation or manual setup. The statement that no log group is configured is directly contradicted by the evidence in the exhibit.

  • ✗

    The Lambda function timed out before writing logs.

    Why it's wrong here

    A Lambda timeout terminates the execution after a configured duration, but log events are written to CloudWatch Logs as they are generated during the invocation. Even if the function times out, a log stream would typically be created with partial logs or a timeout error message. The complete absence of any log stream indicates the logging runtime never successfully wrote, which points to an authorization failure rather than an execution-duration problem.

  • ✓

    The Lambda function's execution role lacks permissions to write to CloudWatch Logs.

    Why this is correct

    To stream logs, Lambda's execution role must have IAM permissions for logs:CreateLogStream and logs:PutLogEvents on the target log group. Even when the log group exists, a restrictive or missing execution role policy prevents the log stream from being created, so no logs appear. Because no log streams exist despite the log group being present, the most plausible root cause is that the role lacks the necessary CloudWatch Logs permissions.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.