Lambda logs are missing because the execution role lacks CloudWatch Logs write permissions

Troubleshoot logging solutions.
Answer Correct answer: A — the Lambda execution role lacked permission to write logs to CloudWatch Logs, so no logs were created.

An AWS Lambda function was misused to alter data, and a security engineer must identify who invoked the function and what output was produced. The engineer cannot find any logs created by the Lambda function in Amazon CloudWatch Logs. Which of the following explains why the logs are not available?

  1. The execution role for the Lambda function did not grant permissions to write log data to CloudWatch Logs. Correct Answer
  2. The Lambda function was invoked by using Amazon API Gateway, so the logs are not stored in CloudWatch Logs.
  3. The execution role for the Lambda function did not grant permissions to write to the Amazon S3 bucket where CloudWatch Logs stores the logs.
  4. The version of the Lambda function that was invoked was not current.

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Lambda writes logs by assuming its execution role; that role must allow CloudWatch Logs write actions. If it does not, the service silently cannot emit logs. API Gateway invocation (B) still routes to the same function and logs normally; CloudWatch Logs is not stored in S3 (C is a misconception); the invoked version (D) does not affect whether logs are created. A is the cause.

If a Lambda function produces no logs in CloudWatch Logs, the usual cause is that its execution role does not grant the logs:CreateLogGroup/CreateLogStream/PutLogEvents permissions (e.g., the AWSLambdaBasicExecutionRole managed policy is missing). Without those permissions the runtime cannot create the log group/stream or write events, so no logs appear. Invocation via API Gateway (B), S3 storage (C), or function version (D) do not prevent logging.

Assuming CloudWatch Logs is stored in S3 (C)—it is not, so an S3 permission is irrelevant. Blaming API Gateway (B) or the function version (D)—neither controls whether the execution role can write logs. The missing execution-role permission (A) is the real cause.

Community Discussion (5 comments)

NimiBes 👍 1 Selected: A
A for me
FunkyFresco 👍 1 Selected: A
Option A is the right choice.
navid1365 👍 1 Selected: A
A is correct: AWS Lambda functions require an execution role that has the appropriate permissions to write log data to CloudWatch Logs. If the execution role does not have the AWSLambdaBasicExecutionRole or similar permissions that include logs:CreateLogGroup, logs:CreateLogStream, and logs:PutLogEvents, the Lambda function will not be able to create or write logs to CloudWatch Logs.
nRaiker 👍 1 Selected: A
The execution role for the Lambda function did not grant permissions to write log data to CloudWatch Logs.
Zek 👍 3
A https://www.examtopics.com/discussions/amazon/view/4864-exam-aws-certified-security-specialty-topic-1-question-104/

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Lambda emits logs by assuming its execution role, which must include permission to create the log group/stream and put log events (AWSLambdaBasicExecutionRole or equivalent). If the role lacks those logs: permissions, the runtime cannot write anything to CloudWatch Logs, so no logs appear for the invocation that altered data.

Why the Other Options Are Wrong

B (invoked via API Gateway) still executes the same function with the same role and logs normally when permitted. C is based on a misconception—CloudWatch Logs is not stored in an S3 bucket, so an S3 permission is irrelevant. D (non-current version) does not prevent log creation; logging works per version. A is the cause.

Community Comment Notes

Community voted A (100). Commenters noted Lambda requires an execution role with CloudWatch Logs write permissions and that AWSLambdaBasicExecutionRole is the usual grant; without it no logs are created. A confirmed.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide