AWS Certified Developer – Associate (DVA-C02)SecurityHard

A developer is building a new application that needs to securely store temporary data generated by users. This data should only be accessible by the user who created it and must expire automatically after a short period. The data is not highly sensitive but requires isolation per user. Which AWS service and access pattern should be used?

  1. AAmazon RDS with user-specific database schemas.
  2. BAmazon S3 with pre-signed URLs.
  3. CAWS Systems Manager Parameter Store with IAM policies.
  4. DAmazon DynamoDB with Cognito Identity Pools for fine-grained access control.
Show answer & explanation

Correct answer: D. Amazon DynamoDB with Cognito Identity Pools for fine-grained access control.

Amazon DynamoDB combined with Cognito Identity Pools can provide fine-grained access control to specific items (user-specific data) and attribute-level access. DynamoDB's Time-to-Live (TTL) feature can be used to automatically expire temporary data, fulfilling all requirements for isolation, user-specific access, and automatic expiration.

Why the other options are wrong

  • A. RDS is a relational database and while it can store user-specific data, managing schemas per user and implementing automatic expiration for individual rows is overly complex for this use case and less 'serverless'.
  • B. S3 with pre-signed URLs provides temporary access to objects but doesn't inherently offer fine-grained access to individual data items within a larger structure or automatic expiration based on item attributes.
  • C. Parameter Store is for configuration and secrets, not for storing temporary, user-specific, expiring data with fine-grained access control.

DynamoDB with Cognito for User Data

Amazon DynamoDB can store user-specific data, and when integrated with Amazon Cognito Identity Pools, allows for fine-grained access control policies to ensure users only access their own data. DynamoDB's TTL feature enables automatic data expiration.

  • DynamoDB stores user-specific data
  • Cognito Identity Pools enable fine-grained access
  • DynamoDB TTL for automatic data expiration

Memory trick: Cognito and DynamoDB team up for expiring user data.

More Security questions