AWS Certified Advanced Networking – Specialty (ANS-C01)Network Security, Compliance, and GovernanceEasy
An innovative startup is developing a new serverless application on AWS, utilizing AWS Lambda, Amazon API Gateway, and Amazon DynamoDB. The application processes user data, and the company needs to control access to specific Lambda functions and DynamoDB tables based on the authenticated user's role and permissions, following the principle of least privilege. Which AWS service should be used to implement this fine-grained access control mechanism?
- AAmazon Cognito
- BAWS WAF
- CAWS Identity and Access Management (IAM)
- DAmazon GuardDuty
Show answer & explanationAnswer & explanation
Correct answer: C. AWS Identity and Access Management (IAM)
AWS Identity and Access Management (IAM) is the fundamental service for managing access to AWS resources. It allows defining granular permissions (roles, policies) to control which authenticated users or services can access specific Lambda functions and DynamoDB tables, adhering to the principle of least privilege.
Why the other options are wrong
- A. Amazon Cognito manages user authentication and authorization but needs IAM to define what those authenticated users can access.
- B. AWS WAF protects web applications from exploits, not for managing fine-grained access to backend services.
- D. Amazon GuardDuty is a threat detection service, not an access control mechanism.
AWS Identity and Access Management (IAM)
A web service that helps you securely control access to AWS resources.
- Manages users, groups, roles, and policies.
- Enforces fine-grained permissions.
- Central to the principle of least privilege.
- Integrates with nearly all AWS services.
Memory trick: IAM is the 'bouncer' and 'rulebook' for who gets into and what they can do with AWS resources.