you can't always create the full environment locally, though, including inputs and connections to other services... local Lambda is an option but there are more elegant solutions too.
You have full control over the incoming event object, so you should have complete control over inputs. Connections to services depends on your setup of course. If you can route to your VPC, you can access those private resources too. By default, it will use your local AWS keypair, but I believe there is a way to assume an IAM role as well.
Sure, but if you can just get full stack traces right off of your production code while it runs, then that's even easier.