How to Fix EventBridge Lambda AccessDeniedException?
A data engineer creates an AWS Lambda function that an Amazon EventBridge event will invoke. When the data engineer tries to invoke the Lambda function by using an EventBridge event, an AccessDeniedException message appears. How should the data engineer resolve the exception?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests the two-sided permission model for EventBridge-to-Lambda invocation, and the trap is confusing the Lambda execution role's trust policy with the Lambda resource-based policy that actually grants EventBridge invoke access.
An EventBridge rule invoking a Lambda function needs correct authorization on both the EventBridge side and the Lambda resource-based policy. This DEA-C01 explanation shows why option B resolves the AccessDeniedException and why the other options do not.
The most common wrong choice is A, because candidates see a trust policy and assume it controls EventBridge's ability to invoke Lambda, when it only controls whether the Lambda service can assume the execution role.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Option B correctly identifies the dual authorization path for an EventBridge rule invoking a Lambda function. EventBridge must have permissions to invoke the function, and Lambda must expose a resource-based policy that grants the events.amazonaws.com service principal or the specific rule lambda:InvokeFunction. The AccessDeniedException occurs because one or both sides of that permission model are missing, so granting both the EventBridge rule's IAM role and the Lambda resource-based policy the necessary permissions resolves it. AWS documentation for scheduled rules shows this exact pattern: the rule needs permission to invoke the function, and the function's policy must allow EventBridge. This is why B is the only option that targets the actual authorization failure.Why the Other Options Are Wrong
Option A confuses the Lambda execution role's trust policy with an invocation policy. The execution role is assumed by the Lambda service to run your function's code; its trust policy controls who can assume that role, not who can invoke the function. EventBridge does not assume the Lambda execution role to invoke the function, so changing that trust policy cannot fix the AccessDeniedException. Option C addresses networking by making the function's subnet private, but the error is an authorization error, not a connectivity or VPC routing issue. Option D refers to EventBridge schema validity and event mapping, which affect event structure and rule matching; they do not grant permission to invoke a Lambda target. None of A, C, or D supplies the missing invoke permission.Community Comment Notes
The comments overwhelmingly favor B for the same reason: artworkad notes that "The lambda resource based policy must allow the events principle" and points to the AWS EventBridge scheduled rule documentation. rpwags and tgv both stress that the EventBridge IAM role and the Lambda resource-based policy must each have the necessary permissions, which matches the two-sided authorization model. GHill1982 argues for A based on trust-policy language, but that reasoning treats role assumption as the invocation path and ignores the Lambda resource policy. The consensus among the other learners, and the AWS documentation referenced, supports B.Official Reference
Exam Strategy
On DEA-C01 IAM questions, separate the service that performs an action from the resource that receives it: EventBridge needs invoke permission, and Lambda needs a resource-based policy naming EventBridge. Check for both before rejecting an answer that mentions two permission layers.
Frequently Asked Questions
Why is the Lambda execution role trust policy not enough for EventBridge?
The trust policy only lets the Lambda service assume the execution role to run code. EventBridge invokes Lambda through the function's resource-based policy, not that trust policy.
Does EventBridge need an IAM role to invoke Lambda?
Option B covers both sides: the EventBridge rule needs invoke permissions, and the Lambda resource-based policy must allow the EventBridge principal. Missing either can produce AccessDeniedException.
Related Analysis
Practice All DEA-C01 Questions
Access 100 questions with complete answers and detailed explanations.
View Full DEA-C01 Practice Test →