Add a resource-based policy to the Lambda function so AWS Config can invoke it
A DevOps team has created a Custom Lambda rule in AWS Config. The rule monitors Amazon Elastic Container Repository (Amazon ECR) policy statements for ecr:* actions. When a noncompliant repository is detected, Amazon EventBridge uses Amazon Simple Notification Service (Amazon SNS) to route the notification to a security team. When the custom AWS Config rule is evaluated, the AWS Lambda function fails to run. Which solution will resolve the issue?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The failure is an invocation authorization problem, not a logic or permissions problem: the function's execution role governs what the code may do once running, while the resource-based policy governs who may invoke it at all, so AWS Config must appear in that policy (A). Option C modifies the execution role, which affects the function's own permissions rather than authorizing Config to call it. Options B and D adjust the SNS topic policy and the ECR repository policies respectively, neither of which is on the invocation path between Config and the function.
A custom AWS Config rule that uses a Lambda function requires AWS Config to be authorized to invoke that function, which is granted through a resource-based policy on the Lambda function itself naming config.amazonaws.com as an allowed invoker. Without that policy the invocation fails even though the function and its logic are correct, so the rule never evaluates. Adding the resource policy resolves the failure at its root cause.
Modifying the Lambda function's execution role to permit the configuration changes (C) — the execution role controls what the function may do once invoked, not whether AWS Config may invoke it, so adding permissions there does not fix an invocation failure. Modifying the SNS topic policy for EventBridge to publish (B) — notifications are downstream of the rule evaluation, which never completes because the function is never invoked. Modifying the ECR repository policies to grant Config access (D) — that would let Config read repository state but still does not authorize it to invoke the Lambda function.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
When a custom AWS Config rule is backed by a Lambda function, AWS Config must invoke that function to evaluate the rule, and the function must explicitly permit it. That authorization is expressed as a resource-based policy on the Lambda function whose principal is the config.amazonaws.com service, granting lambda:InvokeFunction. Because the invocation is rejected without that statement, the rule evaluation fails and no compliance result is produced, which is exactly the reported symptom (A). Adding the resource policy is therefore the minimal change that addresses the root cause. Note that youonebe observed the question's wording is imprecise, since the function does not fail to execute, it fails to be invoked.Why the Other Options Are Wrong
B modifies the SNS topic policy so EventBridge can publish configuration changes. Notification delivery happens after a compliance result exists; since the function is never invoked, no result is produced, so nothing is ever published and the topic policy is not the failing component. C modifies the Lambda function's execution role to include configuration changes for custom rules. The execution role determines what the function may do once it is running, such as reading ECR repository policies; it does not authorize AWS Config to invoke the function, so this change cannot resolve an invocation failure. D modifies the ECR repository policies to grant Config access to the necessary ECR API actions, which would let Config read repository configuration but still leaves Config unable to invoke the Lambda function. A is the correct answer.Community Comment Notes
Community voted A unanimously. ThiagoCruzRJ explained that when a custom AWS Config rule uses a Lambda function, AWS Config needs permission to invoke it, granted by a resource-based policy on the function that explicitly permits the service. jamesf identified this as addressing the root cause of the invocation failure, and d9iceguy put it concisely as a resource policy allowing Config invocation. amehim supplied the shape of the statement, with config.amazonaws.com as the service principal. No alternative received support.Official Reference
Related Analysis
Practice All DOP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full DOP-C02 Practice Test →