Add a resource-based policy to the Lambda function so AWS Config can invoke it

Answer Correct answer: A — add a resource-based policy to the Lambda function granting AWS Config permission to invoke it.

A DevOps team has created a Custom Lambda rule in AWS Config. The rule monitors Amazon Elastic Container Repository (Amazon ECR) policy statements for ecr:* actions. When a noncompliant repository is detected, Amazon EventBridge uses Amazon Simple Notification Service (Amazon SNS) to route the notification to a security team. When the custom AWS Config rule is evaluated, the AWS Lambda function fails to run. Which solution will resolve the issue?

  1. Modify the Lambda function's resource policy to grant AWS Config permission to invoke the function. Correct Answer
  2. Modify the SNS topic policy to include configuration changes for EventBridge to publish to the SNS topic.
  3. Modify the Lambda function's execution role to include configuration changes for custom AWS Config rules.
  4. Modify all the ECR repository policies to grant AWS Config access to the necessary ECR API actions.

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The failure is an invocation authorization problem, not a logic or permissions problem: the function's execution role governs what the code may do once running, while the resource-based policy governs who may invoke it at all, so AWS Config must appear in that policy (A). Option C modifies the execution role, which affects the function's own permissions rather than authorizing Config to call it. Options B and D adjust the SNS topic policy and the ECR repository policies respectively, neither of which is on the invocation path between Config and the function.

A custom AWS Config rule that uses a Lambda function requires AWS Config to be authorized to invoke that function, which is granted through a resource-based policy on the Lambda function itself naming config.amazonaws.com as an allowed invoker. Without that policy the invocation fails even though the function and its logic are correct, so the rule never evaluates. Adding the resource policy resolves the failure at its root cause.

Modifying the Lambda function's execution role to permit the configuration changes (C) — the execution role controls what the function may do once invoked, not whether AWS Config may invoke it, so adding permissions there does not fix an invocation failure. Modifying the SNS topic policy for EventBridge to publish (B) — notifications are downstream of the rule evaluation, which never completes because the function is never invoked. Modifying the ECR repository policies to grant Config access (D) — that would let Config read repository state but still does not authorize it to invoke the Lambda function.

Community Discussion (6 comments)

youonebe 👍 1 Selected: A
Bad wording "fails to run" which sounds like to "fails to execute", which here it actually means "failed to invoke"
ThiagoCruzRJ 👍 2 Selected: A
When you create a custom AWS Config rule that uses a Lambda function, AWS Config needs permission to invoke it. This is done by adding a resource-based policy to the Lambda function that explicitly permits AWS Config to invoke it. Without this permission, AWS Config cannot trigger the Lambda function, leading to the function failing to run.
jamesf 👍 1 Selected: A
Option A is the best choice to resolve the issue. By modifying the Lambda function's resource policy to grant AWS Config permission to invoke the function, we address the root cause of the invocation failure. This ensures that AWS Config can successfully execute the custom rule using the Lambda function.
d9iceguy 👍 2 Selected: A
Resource policy should allow Config invocation
amehim 👍 2
A. Modify the Lambda function's resource policy to grant AWS Config permission to invoke the function. { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "Service": "config.amazonaws.com" }, "Action": "lambda:InvokeFunction", "Resource": "arn:aws:lambda:region:account-id:function:function-name" } ] }
tgv 👍 4
---> A

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

When a custom AWS Config rule is backed by a Lambda function, AWS Config must invoke that function to evaluate the rule, and the function must explicitly permit it. That authorization is expressed as a resource-based policy on the Lambda function whose principal is the config.amazonaws.com service, granting lambda:InvokeFunction. Because the invocation is rejected without that statement, the rule evaluation fails and no compliance result is produced, which is exactly the reported symptom (A). Adding the resource policy is therefore the minimal change that addresses the root cause. Note that youonebe observed the question's wording is imprecise, since the function does not fail to execute, it fails to be invoked.

Why the Other Options Are Wrong

B modifies the SNS topic policy so EventBridge can publish configuration changes. Notification delivery happens after a compliance result exists; since the function is never invoked, no result is produced, so nothing is ever published and the topic policy is not the failing component. C modifies the Lambda function's execution role to include configuration changes for custom rules. The execution role determines what the function may do once it is running, such as reading ECR repository policies; it does not authorize AWS Config to invoke the function, so this change cannot resolve an invocation failure. D modifies the ECR repository policies to grant Config access to the necessary ECR API actions, which would let Config read repository configuration but still leaves Config unable to invoke the Lambda function. A is the correct answer.

Community Comment Notes

Community voted A unanimously. ThiagoCruzRJ explained that when a custom AWS Config rule uses a Lambda function, AWS Config needs permission to invoke it, granted by a resource-based policy on the function that explicitly permits the service. jamesf identified this as addressing the root cause of the invocation failure, and d9iceguy put it concisely as a resource policy allowing Config invocation. amehim supplied the shape of the statement, with config.amazonaws.com as the service principal. No alternative received support.

Official Reference

Related Analysis

Practice All DOP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full DOP-C02 Practice Test →

← Back to DOP-C02 Study Guide