Lambda logs are missing because the execution role lacks CloudWatch Logs write permissions
An AWS Lambda function was misused to alter data, and a security engineer must identify who invoked the function and what output was produced. The engineer cannot find any logs created by the Lambda function in Amazon CloudWatch Logs. Which of the following explains why the logs are not available?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Lambda writes logs by assuming its execution role; that role must allow CloudWatch Logs write actions. If it does not, the service silently cannot emit logs. API Gateway invocation (B) still routes to the same function and logs normally; CloudWatch Logs is not stored in S3 (C is a misconception); the invoked version (D) does not affect whether logs are created. A is the cause.
If a Lambda function produces no logs in CloudWatch Logs, the usual cause is that its execution role does not grant the logs:CreateLogGroup/CreateLogStream/PutLogEvents permissions (e.g., the AWSLambdaBasicExecutionRole managed policy is missing). Without those permissions the runtime cannot create the log group/stream or write events, so no logs appear. Invocation via API Gateway (B), S3 storage (C), or function version (D) do not prevent logging.
Assuming CloudWatch Logs is stored in S3 (C)—it is not, so an S3 permission is irrelevant. Blaming API Gateway (B) or the function version (D)—neither controls whether the execution role can write logs. The missing execution-role permission (A) is the real cause.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.