How to Fix EventBridge Lambda AccessDeniedException?

Apply authorization mechanisms. Automate data processing by using AWS services.
Answer Correct answer: B — grant EventBridge the needed IAM permissions and add a Lambda resource-based policy that allows EventBridge to invoke the function.

A data engineer creates an AWS Lambda function that an Amazon EventBridge event will invoke. When the data engineer tries to invoke the Lambda function by using an EventBridge event, an AccessDeniedException message appears. How should the data engineer resolve the exception?

  1. Ensure that the trust policy of the Lambda function execution role allows EventBridge to assume the execution role.
  2. Ensure that both the IAM role that EventBridge uses and the Lambda function's resource-based policy have the necessary permissions. Correct Answer
  3. Ensure that the subnet where the Lambda function is deployed is configured to be a private subnet.
  4. Ensure that EventBridge schemas are valid and that the event mapping configuration is correct.

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests the two-sided permission model for EventBridge-to-Lambda invocation, and the trap is confusing the Lambda execution role's trust policy with the Lambda resource-based policy that actually grants EventBridge invoke access.

An EventBridge rule invoking a Lambda function needs correct authorization on both the EventBridge side and the Lambda resource-based policy. This DEA-C01 explanation shows why option B resolves the AccessDeniedException and why the other options do not.

The most common wrong choice is A, because candidates see a trust policy and assume it controls EventBridge's ability to invoke Lambda, when it only controls whether the Lambda service can assume the execution role.

Community Discussion (6 comments)

artworkad 👍 5 Selected: B
The lambda resource based policy must allow the events principle to invoke the lambda function. https://docs.aws.amazon.com/eventbridge/latest/userguide/eb-run-lambda-schedule.html#eb-schedule-create-rule and https://docs.aws.amazon.com/eventbridge/latest/userguide/eb-run-lambda-schedule.html#eb-schedule-create-rule Amazon SQS, Amazon SNS, Lambda, CloudWatch Logs, and EventBridge bus targets do not use roles, and permissions to EventBridge must be granted via a resource policy.
Shanmahi 👍 2 Selected: B
Option B
HunkyBunky 👍 3 Selected: B
Only B - makes sense
rpwags 👍 3 Selected: B
"B" is corect because the only way to resolve the AccessDeniedException message is to make sure both the IAM role for EventBridge and the Lambda function's resource-based policy have the necessary permissions.
GHill1982 👍 2 Selected: A
The trust policy is what grants an AWS service permission to use the role on behalf of the user. Without this trust relationship, EventBridge won’t have the necessary permissions to invoke the Lambda function.
tgv 👍 3 Selected: B
IAM Role for EventBridge: EventBridge needs permission to invoke the Lambda function. Lambda Resource-Based Policy: The Lambda function must have a resource-based policy that allows EventBridge to invoke it.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Option B correctly identifies the dual authorization path for an EventBridge rule invoking a Lambda function. EventBridge must have permissions to invoke the function, and Lambda must expose a resource-based policy that grants the events.amazonaws.com service principal or the specific rule lambda:InvokeFunction. The AccessDeniedException occurs because one or both sides of that permission model are missing, so granting both the EventBridge rule's IAM role and the Lambda resource-based policy the necessary permissions resolves it. AWS documentation for scheduled rules shows this exact pattern: the rule needs permission to invoke the function, and the function's policy must allow EventBridge. This is why B is the only option that targets the actual authorization failure.

Why the Other Options Are Wrong

Option A confuses the Lambda execution role's trust policy with an invocation policy. The execution role is assumed by the Lambda service to run your function's code; its trust policy controls who can assume that role, not who can invoke the function. EventBridge does not assume the Lambda execution role to invoke the function, so changing that trust policy cannot fix the AccessDeniedException. Option C addresses networking by making the function's subnet private, but the error is an authorization error, not a connectivity or VPC routing issue. Option D refers to EventBridge schema validity and event mapping, which affect event structure and rule matching; they do not grant permission to invoke a Lambda target. None of A, C, or D supplies the missing invoke permission.

Community Comment Notes

The comments overwhelmingly favor B for the same reason: artworkad notes that "The lambda resource based policy must allow the events principle" and points to the AWS EventBridge scheduled rule documentation. rpwags and tgv both stress that the EventBridge IAM role and the Lambda resource-based policy must each have the necessary permissions, which matches the two-sided authorization model. GHill1982 argues for A based on trust-policy language, but that reasoning treats role assumption as the invocation path and ignores the Lambda resource policy. The consensus among the other learners, and the AWS documentation referenced, supports B.

Official Reference

Exam Strategy

On DEA-C01 IAM questions, separate the service that performs an action from the resource that receives it: EventBridge needs invoke permission, and Lambda needs a resource-based policy naming EventBridge. Check for both before rejecting an answer that mentions two permission layers.

Frequently Asked Questions

Why is the Lambda execution role trust policy not enough for EventBridge?

The trust policy only lets the Lambda service assume the execution role to run code. EventBridge invokes Lambda through the function's resource-based policy, not that trust policy.

Does EventBridge need an IAM role to invoke Lambda?

Option B covers both sides: the EventBridge rule needs invoke permissions, and the Lambda resource-based policy must allow the EventBridge principal. Missing either can produce AccessDeniedException.

Related Analysis

Practice All DEA-C01 Questions

Access 100 questions with complete answers and detailed explanations.

View Full DEA-C01 Practice Test →

← Back to DEA-C01 Study Guide