AWS Certified Advanced Networking – Specialty (ANS-C01)Network Security, Compliance, and GovernanceHard

A software-as-a-service (SaaS) company hosts its multi-tenant application on AWS. They need to restrict access to their Amazon DynamoDB tables based on the tenant ID present in the user's IAM role session. This ensures that a tenant can only access their own data. Which IAM policy condition key should be used to enforce this fine-grained access control?

  1. Aaws:SourceIp
  2. Bdynamodb:LeadingKeys
  3. Cdynamodb:Attributes
  4. Ddynamodb:FederatedId
Show answer & explanation

Correct answer: B. dynamodb:LeadingKeys

The 'dynamodb:LeadingKeys' condition key allows you to restrict access to items in a DynamoDB table based on the primary key's partition key. In a multi-tenant scenario, the tenant ID is often used as the partition key (or a leading part of it), enabling fine-grained access control to ensure tenants only access their own data.

Why the other options are wrong

  • A. aws:SourceIp restricts access based on the IP address of the requester, not tenant ID.
  • C. dynamodb:Attributes controls access to specific attributes within an item, not item-level access based on the primary key.
  • D. dynamodb:FederatedId is used for federated identity scenarios, but not specifically for restricting access based on a tenant ID within the primary key of a DynamoDB table.

DynamoDB Fine-Grained Access Control (LeadingKeys)

Using the 'dynamodb:LeadingKeys' condition key in an IAM policy allows you to restrict access to DynamoDB items based on the values of the partition key or sort key, enabling multi-tenant isolation.

  • Enforces tenant data isolation.
  • Uses the primary key (partition key/sort key) for access control.
  • Applied in IAM policies for specific DynamoDB actions.

Memory trick: Leading Keys Pave the Way for Tenant-Specific Data.

More Network Security, Compliance, and Governance questions