SOA-C02 rds:DownloadDBLogFilePortion Practice Question
A SysOps administrator needs to grant a developer access to view only the logs of a specific Amazon RDS instance. Which IAM action should be allowed?
⚠ Common exam trap
Many candidates think `rds:DescribeDBLogFiles` (Option C) is sufficient to view logs, but it only lists log files. To actually view the log content, you need `rds:DownloadDBLogFilePortion`. The question specifies 'view only the logs', which implies viewing the content, not just listing files.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
rds:DownloadDBLogFilePortion
`rds:DownloadDBLogFilePortion` grants permission to download and view the contents of a log file for a specific RDS instance. The question asks for the action to 'view only the logs', which requires retrieving the log file content. `rds:DescribeDBLogFiles` only lists available log files, not the actual log data. Therefore, to view logs, the developer needs the `DownloadDBLogFilePortion` permission.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
rds:DownloadDBLogFilePortion
Why this is correct
rds:DownloadDBLogFilePortion permits retrieving individual log file contents for the specified RDS instance, giving read-only visibility without granting modify or delete permissions. This satisfies the least-privilege requirement of viewing only logs, unlike broader rds actions that expose instance configuration or management.
- ✗
rds:DescribeDBInstances
Why it's wrong here
DescribeDBInstances returns instance metadata such as engine version, endpoint and status; it exposes no log content, so the developer still cannot read logs. It is tempting because it is the standard discovery call for inventory and monitoring tooling, and would be correct when the task is listing or auditing RDS instances rather than viewing their logs.
- ✗
rds:DescribeDBLogFiles
Why it's wrong here
DescribeDBLogFiles only lists the available log file names and sizes for an instance; it returns no log entries, so the developer cannot actually read the logs. It is tempting because it is the correct first call when enumerating which log files exist before downloading them with DownloadDBLogFilePortion.
- ✗
rds:DescribeEvents
Why it's wrong here
DescribeEvents returns recent instance-level event notifications, such as failovers and maintenance windows, not the database error or slow-query logs. It is tempting because it is the natural action for monitoring instance health and operational activity, and would be correct when the requirement is tracking RDS events rather than reading log files.
Go deeper
Related to this question
About these practice questions
One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.