How to resolve AccessDeniedException when Lambda pushes events to EventBridge?
A developer is building an event-driven application by using AWS Lambda and Amazon EventBridge. The Lambda function needs to push events to an EventBridge event bus. The developer uses an SDK to run the PutEvents EventBridge action and specifies no credentials in the code. After deploying the Lambda function, the developer notices that the function is failing and there are AccessDeniedException errors in the logs. How should the developer resolve this issue?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests understanding of identity-based vs. resource-based policies: the Lambda execution role (identity-based) must grant outbound permissions for the SDK call, not a resource-based policy on the Lambda itself.
When a Lambda function uses the AWS SDK to call PutEvents on EventBridge without specifying credentials, it relies on its execution role for permissions. Missing PutEvents permissions on the Lambda execution role cause AccessDeniedException errors.
Candidates often choose D, confusing the resource-based policy on the Lambda function (which controls who can invoke the Lambda) with the identity-based permissions the Lambda needs to call other AWS services.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Understanding Lambda Permissions for Outbound AWS API Calls
When an AWS Lambda function needs to interact with other AWS services — such as calling Amazon EventBridge's PutEvents API — it must have the appropriate IAM permissions. Because the developer did not hard-code credentials in the SDK call, the Lambda function automatically uses the temporary security credentials provided by its execution role.
Why Option C is Correct
The Lambda execution role is an IAM role that defines what AWS services and resources the Lambda function is allowed to access. To resolve the AccessDeniedException, the developer must attach an inline or managed policy to this execution role granting the events:PutEvents permission on the target EventBridge event bus. This is the standard, identity-based permission model for outbound calls from Lambda.
Why the Other Options Are Wrong
- Option A (VPC peering): EventBridge is a regional AWS service accessed via public AWS API endpoints. VPC peering is irrelevant here and does not affect IAM authorization.
- Option B (Modify AWS credentials): The scenario explicitly states no credentials are specified in the code. Best practice is to avoid hard-coded credentials and rely on the execution role.
- Option D (Resource-based policy on Lambda): A resource-based policy attached to the Lambda function controls who can invoke the function (e.g., allowing EventBridge to trigger the Lambda). It does not grant the Lambda function permissions to call other services like EventBridge. This is the most common trap — candidates confuse inbound invocation permissions with outbound API call permissions.
Community Insight
As noted by community members, the distinction is clear: IAM roles on the sender grant outbound permissions, while resource-based policies on the receiver (the EventBridge event bus) control who can send events to it. Since the Lambda is the sender initiating the PutEvents call, its execution role must be updated.
Official Reference
Exam Strategy
When a Lambda function calls another AWS service and receives AccessDenied, always check the Lambda execution role first. Remember: resource-based policies on the Lambda control inbound invocations, while the execution role controls outbound API permissions.
Related Analysis
Practice All DVA-C02 Questions
Access 100 questions with complete answers and detailed explanations.
View Full DVA-C02 Practice Test →