Courseiva
Security and Compliance →easyMultiple Choice

SOA-C02 rds:DownloadDBLogFilePortion Practice Question

A SysOps administrator needs to grant a developer access to view only the logs of a specific Amazon RDS instance. Which IAM action should be allowed?

⚠ Common exam trap

Many candidates think `rds:DescribeDBLogFiles` (Option C) is sufficient to view logs, but it only lists log files. To actually view the log content, you need `rds:DownloadDBLogFilePortion`. The question specifies 'view only the logs', which implies viewing the content, not just listing files.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

rds:DownloadDBLogFilePortion

`rds:DownloadDBLogFilePortion` grants permission to download and view the contents of a log file for a specific RDS instance. The question asks for the action to 'view only the logs', which requires retrieving the log file content. `rds:DescribeDBLogFiles` only lists available log files, not the actual log data. Therefore, to view logs, the developer needs the `DownloadDBLogFilePortion` permission.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    rds:DownloadDBLogFilePortion

    Why this is correct

    rds:DownloadDBLogFilePortion permits retrieving individual log file contents for the specified RDS instance, giving read-only visibility without granting modify or delete permissions. This satisfies the least-privilege requirement of viewing only logs, unlike broader rds actions that expose instance configuration or management.

  • ✗

    rds:DescribeDBInstances

    Why it's wrong here

    DescribeDBInstances returns instance metadata such as engine version, endpoint and status; it exposes no log content, so the developer still cannot read logs. It is tempting because it is the standard discovery call for inventory and monitoring tooling, and would be correct when the task is listing or auditing RDS instances rather than viewing their logs.

  • ✗

    rds:DescribeDBLogFiles

    Why it's wrong here

    DescribeDBLogFiles only lists the available log file names and sizes for an instance; it returns no log entries, so the developer cannot actually read the logs. It is tempting because it is the correct first call when enumerating which log files exist before downloading them with DownloadDBLogFilePortion.

  • ✗

    rds:DescribeEvents

    Why it's wrong here

    DescribeEvents returns recent instance-level event notifications, such as failovers and maintenance windows, not the database error or slow-query logs. It is tempting because it is the natural action for monitoring instance health and operational activity, and would be correct when the requirement is tracking RDS events rather than reading log files.

About these practice questions

One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.