SOA-C02 Monitoring, Logging, and Remediation Practice Question
Exhibit
Refer to the exhibit.
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": "logs:PutLogEvents",
"Resource": "arn:aws:logs:us-east-1:123456789012:log-group:/aws/lambda/MyFunction:*"
}
]
}Refer to the exhibit. A Lambda function is unable to write logs to CloudWatch Logs. The IAM role attached to the Lambda function includes the policy shown. What is the issue?
⚠ Common exam trap
Watch out — candidates often assume a wildcard on the log group ARN (e.g., `log-group:*`) covers all actions, but AWS requires the log-stream component for write operations like `PutLogEvents`, causing a subtle permissions failure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The resource ARN does not include a log-stream component.
The Lambda function's IAM policy grants permissions for `logs:CreateLogGroup`, `logs:CreateLogStream`, and `logs:PutLogEvents` on the resource ARN `arn:aws:logs:us-east-1:123456789012:log-group:/aws/lambda/MyFunction:*`. However, this ARN only specifies the log group and a wildcard for log streams, which is insufficient for the `logs:PutLogEvents` action. The `logs:PutLogEvents` action requires a resource ARN that includes a specific log-stream component (e.g., `arn:aws:logs:us-east-1:123456789012:log-group:/aws/lambda/MyFunction:log-stream:*`), because the API call targets a particular log stream within the log group. Without this, the Lambda function cannot write logs, resulting in a permissions error.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The log group name is incorrect.
Why it's wrong here
The log group name in the IAM policy resource ARN exactly matches the log group that the Lambda function is configured to write to. If it did not, CloudWatch Logs would throw a resource-not-found or a mismatch, but the actual failure is a permissions error caused by the policy's resource scope. Because the log group name is valid and correctly referenced, it is not the source of the problem.
- ✗
The policy effect is Deny.
Why it's wrong here
The exhibit clearly shows the policy statement has an Effect of 'Allow', so this is not a deny. Even if an explicit deny were present, the error would occur regardless of resource ARN, but the policy is an allow. The issue is not the effect but the resource definition, which lacks the required log-stream component for the PutLogEvents action. Thus, the effect is correct and not the cause.
- ✗
The 'logs:PutLogEvents' action is not allowed.
Why it's wrong here
The IAM policy does include 'logs:PutLogEvents' in the Action list, so the action is permitted by the policy. However, the Resource for that action is set to the log-group ARN only, and PutLogEvents requires a log-stream ARN as the resource. Simply allowing the action without targeting the correct resource type prevents the Lambda function from writing logs. Therefore, the action is allowed but ineffectively scoped.
- ✓
The resource ARN does not include a log-stream component.
Why this is correct
For PutLogEvents, IAM must authorize against the log-stream ARN, which follows the pattern arn:aws:logs:region:account-id:log-group:log-group-name:log-stream:log-stream-name. The policy's resource ARN stops at 'log-group:my-log-group' and lacks the ':log-stream:...' component, so the permission does not match the API call's resource. To allow writes, the resource must be 'arn:aws:logs:region:account-id:log-group:my-log-group:log-stream:*' or a specific stream name. This is the root cause of the Lambda function's inability to write logs.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.