AWS Certified Advanced Networking – Specialty (ANS-C01)Network Security, Compliance, and GovernanceHard
A software-as-a-service (SaaS) company hosts its multi-tenant application on AWS. They need to restrict access to their Amazon DynamoDB tables based on the tenant ID present in the user's IAM role session. This ensures that a tenant can only access their own data. Which IAM policy condition key should be used to enforce this fine-grained access control?
- Aaws:SourceIp
- Bdynamodb:LeadingKeys
- Cdynamodb:Attributes
- Ddynamodb:FederatedId
Show answer & explanationAnswer & explanation
Correct answer: B. dynamodb:LeadingKeys
The 'dynamodb:LeadingKeys' condition key allows you to restrict access to items in a DynamoDB table based on the primary key's partition key. In a multi-tenant scenario, the tenant ID is often used as the partition key (or a leading part of it), enabling fine-grained access control to ensure tenants only access their own data.
Why the other options are wrong
- A. aws:SourceIp restricts access based on the IP address of the requester, not tenant ID.
- C. dynamodb:Attributes controls access to specific attributes within an item, not item-level access based on the primary key.
- D. dynamodb:FederatedId is used for federated identity scenarios, but not specifically for restricting access based on a tenant ID within the primary key of a DynamoDB table.
DynamoDB Fine-Grained Access Control (LeadingKeys)
Using the 'dynamodb:LeadingKeys' condition key in an IAM policy allows you to restrict access to DynamoDB items based on the values of the partition key or sort key, enabling multi-tenant isolation.
- Enforces tenant data isolation.
- Uses the primary key (partition key/sort key) for access control.
- Applied in IAM policies for specific DynamoDB actions.
Memory trick: Leading Keys Pave the Way for Tenant-Specific Data.