AWS Certified Advanced Networking – Specialty (ANS-C01)Network Security, Compliance, and GovernanceMedium

A global Software-as-a-Service (SaaS) provider uses Amazon DynamoDB for its multi-tenant application. Each tenant has a unique identifier, and the application needs to ensure that users can only access data belonging to their own tenant within DynamoDB. The solution must provide fine-grained access control based on the tenant ID present in the user's authentication context, without requiring extensive application-level logic for authorization. Which IAM policy configuration, leveraging DynamoDB's capabilities, would best achieve this?

  1. AUse an IAM policy with a Condition key `dynamodb:LeadingKeys` to match the tenant ID in the partition key.
  2. BImplement an IAM policy that allows access to all DynamoDB tables, and filter results at the application layer.
  3. CUse AWS WAF to filter DynamoDB queries based on tenant ID before they reach the database.
  4. DApply resource-based policies directly to each DynamoDB item to restrict access.
Show answer & explanation

Correct answer: A. Use an IAM policy with a Condition key `dynamodb:LeadingKeys` to match the tenant ID in the partition key.

DynamoDB supports fine-grained access control through IAM policies, specifically using the `dynamodb:LeadingKeys` condition key. This allows restricting access to items where the partition key (or the first part of a composite primary key) matches a specific value, such as a tenant ID derived from the authenticated user's context, without complex application-level filtering.

Why the other options are wrong

  • B. Allowing access to all DynamoDB tables and filtering at the application layer is less secure and violates the principle of least privilege, as the application could potentially access data from other tenants.
  • C. AWS WAF is a web application firewall and does not interact directly with DynamoDB queries for fine-grained access control; it operates at the HTTP/S layer for web traffic.
  • D. DynamoDB does not directly support resource-based policies on individual items; policies are typically applied at the table level or through IAM roles.

DynamoDB Fine-Grained Access (LeadingKeys)

Leverages IAM policies with the `dynamodb:LeadingKeys` condition to grant fine-grained access to DynamoDB items based on the item's partition key.

  • Enables tenant isolation in multi-tenant applications.
  • Access is restricted at the database level, enforcing least privilege.
  • Reduces the need for complex authorization logic within the application.
  • The condition key matches the partition key (or the first part of a composite key) of DynamoDB items.

Memory trick: LeadingKeys lead to tenant's data, no peeking allowed.

More Network Security, Compliance, and Governance questions