you have written a lambda function designed to attach a restrictive iam policy, which denies access to create internet gateways to a specific user, and found it to be creating unauthorized internet gateways in your secure vpc. however, during testing you find that the function doesn't work as expected and the user's permissions remain the same. which of the following would you to do to investigate this?