How to resolve AccessDeniedException when Lambda pushes events to EventBridge?

A developer is building an event-driven application by using AWS Lambda and Amazon EventBridge. The Lambda function needs to push events to an EventBridge event bus. The developer uses an SDK to run the PutEvents EventBridge action and specifies no credentials in the code. After deploying the Lambda function, the developer notices that the function is failing and there are AccessDeniedException errors in the logs. How should the developer resolve this issue?

  1. Configure a VPC peering connection between the Lambda function and EventBridge.
  2. Modify their AWS credentials to include permissions for the PutEvents EventBridge action.
  3. Modify the Lambda function execution role to include permissions for the PutEvents EventBridge action. Source Reference Answer
  4. Add a resource-based policy to the Lambda function to include permissions for the PutEvents EventBridge action.

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests understanding of identity-based vs. resource-based policies: the Lambda execution role (identity-based) must grant outbound permissions for the SDK call, not a resource-based policy on the Lambda itself.

When a Lambda function uses the AWS SDK to call PutEvents on EventBridge without specifying credentials, it relies on its execution role for permissions. Missing PutEvents permissions on the Lambda execution role cause AccessDeniedException errors.

Candidates often choose D, confusing the resource-based policy on the Lambda function (which controls who can invoke the Lambda) with the identity-based permissions the Lambda needs to call other AWS services.

Community Discussion (6 comments)

examuserss 👍 1 Selected: C
Correct Answer: C. Modify the Lambda function execution role to include permissions for the PutEvents EventBridge action. The developer should update the Lambda function's execution role to include the necessary permissions for the PutEvents action on the EventBridge event bus. This will resolve the AccessDeniedException errors and allow the Lambda function to push events to EventBridge.
65703c1 👍 1 Selected: C
C is the correct answer.
be1dca8 👍 3
C you use IAM roles on the sender event bus to give the sender event bus permission to send events to the receiver event bus. You use Resource-based policies on the receiver event bus to give the receiver event bus permission to receive events from the sender event bus. https://docs.aws.amazon.com/eventbridge/latest/userguide/eb-bus-to-bus.html
DeaconStJohn 👍 2 Selected: C
As lambda is initiating the action (push), permission must be attached the the execution role.
outrageous7 👍 2 Selected: C
Lambda Execution Role (IAM Role) • Grants the Lambda function permissions to AWS services / resources
KarBiswa 👍 1 Selected: D
https://docs.aws.amazon.com/eventbridge/latest/userguide/eb-event-bus-perms.html

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Understanding Lambda Permissions for Outbound AWS API Calls

When an AWS Lambda function needs to interact with other AWS services — such as calling Amazon EventBridge's PutEvents API — it must have the appropriate IAM permissions. Because the developer did not hard-code credentials in the SDK call, the Lambda function automatically uses the temporary security credentials provided by its execution role.

Why Option C is Correct

The Lambda execution role is an IAM role that defines what AWS services and resources the Lambda function is allowed to access. To resolve the AccessDeniedException, the developer must attach an inline or managed policy to this execution role granting the events:PutEvents permission on the target EventBridge event bus. This is the standard, identity-based permission model for outbound calls from Lambda.

Why the Other Options Are Wrong

  • Option A (VPC peering): EventBridge is a regional AWS service accessed via public AWS API endpoints. VPC peering is irrelevant here and does not affect IAM authorization.
  • Option B (Modify AWS credentials): The scenario explicitly states no credentials are specified in the code. Best practice is to avoid hard-coded credentials and rely on the execution role.
  • Option D (Resource-based policy on Lambda): A resource-based policy attached to the Lambda function controls who can invoke the function (e.g., allowing EventBridge to trigger the Lambda). It does not grant the Lambda function permissions to call other services like EventBridge. This is the most common trap — candidates confuse inbound invocation permissions with outbound API call permissions.

Community Insight

As noted by community members, the distinction is clear: IAM roles on the sender grant outbound permissions, while resource-based policies on the receiver (the EventBridge event bus) control who can send events to it. Since the Lambda is the sender initiating the PutEvents call, its execution role must be updated.

Official Reference

Exam Strategy

When a Lambda function calls another AWS service and receives AccessDenied, always check the Lambda execution role first. Remember: resource-based policies on the Lambda control inbound invocations, while the execution role controls outbound API permissions.

Related Analysis

Practice All DVA-C02 Questions

Access 100 questions with complete answers and detailed explanations.

View Full DVA-C02 Practice Test →

← Back to DVA-C02 Study Guide