AWS Certified Developer – Associate (DVA-C02)Troubleshooting and MonitoringEasy
A developer is troubleshooting an Amazon S3 event notification configured to invoke an AWS Lambda function. The Lambda function is not being invoked when new objects are uploaded to the S3 bucket, despite the objects appearing successfully in the bucket. Reviewing the S3 event configuration in the AWS Management Console shows that the notification is correctly pointing to the Lambda function. What is the MOST likely misconfiguration?
- AThe S3 event notification is configured to trigger on the wrong event type (e.g., 'Delete' instead of 'Put').
- BThe Lambda function's resource-based policy does not grant S3 permission to invoke the function.
- CThe S3 bucket policy does not grant the Lambda function permission to read objects from the bucket.
- DThe Lambda function is configured with an insufficient memory limit, causing invocation failures.
Show answer & explanationAnswer & explanation
Correct answer: B. The Lambda function's resource-based policy does not grant S3 permission to invoke the function.
For S3 to invoke a Lambda function, the Lambda function's resource-based policy must explicitly grant S3 permission to invoke it. Without this permission, S3 cannot trigger the function, even if the notification configuration is correct from the S3 side.
Why the other options are wrong
- A. The question states the configuration 'is correctly pointing to the Lambda function', implying the event type is correct. If it were wrong, the issue would be no notification, not an invocation failure due to permissions.
- C. The S3 bucket policy governs access to objects within the bucket. While important for the Lambda function to *process* the object, it doesn't prevent S3 from *invoking* the function in the first place.
- D. Insufficient memory would cause the Lambda function to fail *during* invocation, not prevent the invocation from happening at all.
S3-Lambda Invocation Policy
For S3 to trigger a Lambda function via event notifications, the Lambda function's resource-based policy must explicitly grant S3 permission to invoke it.
- Use `lambda:AddPermission` or configure in console.
- Source ARN must match the S3 bucket triggering the event.
- Prevents unauthorized services from invoking Lambda.
Memory trick: S3 needs a 'permission slip' to talk to Lambda.