A developer is building a new application that needs to securely store temporary data generated by users. This data should only be accessible by the user who created it and must expire automatically after a short period. The data is not highly sensitive but requires isolation per user. Which AWS service and access pattern should be used?
- AAmazon RDS with user-specific database schemas.
- BAmazon S3 with pre-signed URLs.
- CAWS Systems Manager Parameter Store with IAM policies.
- DAmazon DynamoDB with Cognito Identity Pools for fine-grained access control.
Show answer & explanationAnswer & explanation
Correct answer: D. Amazon DynamoDB with Cognito Identity Pools for fine-grained access control.
Amazon DynamoDB combined with Cognito Identity Pools can provide fine-grained access control to specific items (user-specific data) and attribute-level access. DynamoDB's Time-to-Live (TTL) feature can be used to automatically expire temporary data, fulfilling all requirements for isolation, user-specific access, and automatic expiration.
Why the other options are wrong
- A. RDS is a relational database and while it can store user-specific data, managing schemas per user and implementing automatic expiration for individual rows is overly complex for this use case and less 'serverless'.
- B. S3 with pre-signed URLs provides temporary access to objects but doesn't inherently offer fine-grained access to individual data items within a larger structure or automatic expiration based on item attributes.
- C. Parameter Store is for configuration and secrets, not for storing temporary, user-specific, expiring data with fine-grained access control.
DynamoDB with Cognito for User Data
Amazon DynamoDB can store user-specific data, and when integrated with Amazon Cognito Identity Pools, allows for fine-grained access control policies to ensure users only access their own data. DynamoDB's TTL feature enables automatic data expiration.
- DynamoDB stores user-specific data
- Cognito Identity Pools enable fine-grained access
- DynamoDB TTL for automatic data expiration
Memory trick: Cognito and DynamoDB team up for expiring user data.