SCS-C02 Security Logging and Monitoring Practice Question
Network Topology
Refer to the exhibit. After invoking the Lambda function, why are there no log streams in the log group?
⚠ Common exam trap
SCS-C02 often tests the misconception that Lambda needs a pre-created log group or that timeouts/retention settings suppress log delivery, when the real culprit in an empty log group is almost always missing CloudWatch Logs permissions on the execution role.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The Lambda function's execution role lacks permissions to write to CloudWatch Logs.
Lambda writes logs to CloudWatch Logs using the permissions granted to its execution role. If that role lacks the required actions (logs:CreateLogGroup, logs:CreateLogStream, logs:PutLogEvents), the function still executes but the log writes are silently denied, so no log streams appear in the log group. This is the classic cause of an empty log group after a successful invocation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The CloudWatch Logs log group retention policy is set to 0 days.
Why it's wrong here
A CloudWatch Logs retention policy controls how long log events are retained after they are written, not whether a log group or log stream is created. The value 0 days is not a valid retention period in AWS (minimum is 1 day), and even an immediate-expiration policy would only delete events that already exist. Since no log streams are present at all, the problem occurs before any log event is written, which is unrelated to retention.
- ✗
The Lambda function is not configured with a CloudWatch Logs log group.
Why it's wrong here
The exhibit explicitly shows a log group in the describe-log-groups output that matches the Lambda function's expected name, such as /aws/lambda/your-function-name. Lambda automatically uses this convention, and the log group's existence confirms that the function is associated with it, either from automatic creation during an earlier invocation or manual setup. The statement that no log group is configured is directly contradicted by the evidence in the exhibit.
- ✗
The Lambda function timed out before writing logs.
Why it's wrong here
A Lambda timeout terminates the execution after a configured duration, but log events are written to CloudWatch Logs as they are generated during the invocation. Even if the function times out, a log stream would typically be created with partial logs or a timeout error message. The complete absence of any log stream indicates the logging runtime never successfully wrote, which points to an authorization failure rather than an execution-duration problem.
- ✓
The Lambda function's execution role lacks permissions to write to CloudWatch Logs.
Why this is correct
To stream logs, Lambda's execution role must have IAM permissions for logs:CreateLogStream and logs:PutLogEvents on the target log group. Even when the log group exists, a restrictive or missing execution role policy prevents the log stream from being created, so no logs appear. Because no log streams exist despite the log group being present, the most plausible root cause is that the role lacks the necessary CloudWatch Logs permissions.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.