A Security Engineer has created an Amazon CloudWatch event that invokes an AWS Lambda function daily. The Lambda function runs an Amazon Athena query that checks AWS CloudTrail logs in Amazon S3 to detect whether any IAM user accounts or credentials have been created in the past 30 days. The results of the Athena query are created in the same S3 bucket. The Engineer runs a test execution of the Lambda function via the AWS Console, and the function runs successfully. After several minutes, the Engineer finds that his Athena query has failed with the error message: "Insufficient Permissions". The IAM permissions of the Security Engineer and the Lambda function are shown below: Security Engineer
Lambda function execution role
What is causing the error?
A) The Lambda function does not have permissions to start the Athena query execution.
B) The Security Engineer does not have permissions to start the Athena query execution.
C) The Athena service does not support invocation through Lambda.
D) The Lambda function does not have permissions to access the CloudTrail S3 bucket.
Correct Answer:
Verified
Q1: A Security Administrator is performing a log
Q2: During a recent internal investigation, it was
Q4: An organization wants to deploy a three-tier
Q5: An application has a requirement to be
Q6: A Security Engineer must design a solution
Q7: A Security Administrator has a website hosted
Q8: A water utility company uses a number
Q9: A threat assessment has identified a risk
Q10: An organization has a system in AWS
Q11: An organization policy states that all encryption
Unlock this Answer For Free Now!
View this answer and more for free by performing one of the following actions
Scan the QR code to install the App and get 2 free unlocks
Unlock quizzes for free by uploading documents