AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question
A CloudOps engineer configured a CloudWatch alarm to invoke a Lambda function directly for automated remediation. The alarm is correctly transitioning to the ALARM state, but the Lambda function is not being invoked. Logs show no invocation attempts. What is the MOST likely cause of this issue?
The Lambda function's IAM execution role does not grant permission to be invoked by CloudWatch.
The alarm action must first send a notification to an SNS topic, which then triggers the Lambda function.
An Amazon EventBridge rule must be created to route the alarm state change to the Lambda function.
The Lambda function is missing a resource-based policy granting invoke permissions to the CloudWatch Alarms service principal.
As of late 2023, CloudWatch alarms can invoke Lambda functions directly. For this to work, the Lambda function must have a resource-based policy that grants the CloudWatch Alarms service principal (lambda.alarms.cloudwatch.amazonaws.com) permission to invoke it. Without this permission, CloudWatch cannot trigger the function, even if the alarm action is configured correctly. The Lambda function's execution role defines what the function can do, not who can invoke it. The old method of using an SNS topic is no longer required for this direct integration. Finally, using EventBridge is an alternative integration pattern, not a solution for a failing direct invocation permission.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a resource-based policy in AWS?
Open an interactive chat with Bash
Why does the CloudWatch Alarms service principal need permissions to invoke a Lambda function?
Open an interactive chat with Bash
How is the integration between CloudWatch and Lambda different from using SNS or EventBridge?
Open an interactive chat with Bash
AWS Certified CloudOps Engineer Associate SOA-C03
Monitoring, Logging, Analysis, Remediation, and Performance Optimization
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .