AWS Certified Developer – Associate (DVA-C02)Development with AWS ServicesEasy

A developer is building a serverless application using AWS Lambda and Amazon DynamoDB. The Lambda function needs to perform `PutItem` operations on a DynamoDB table. To ensure secure and efficient access, how should the developer grant the Lambda function permissions to access DynamoDB?

  1. AEmbed the DynamoDB access key and secret key directly in the Lambda function's environment variables.
  2. BCreate an IAM role with `PutItem` permissions for the DynamoDB table and associate this role with the Lambda function.
  3. CAttach an IAM policy directly to the DynamoDB table granting `PutItem` permissions to the Lambda function's ARN.
  4. DGrant `PutItem` permissions to the 'Everyone' principal on the DynamoDB table's resource-based policy.
Show answer & explanation

Correct answer: B. Create an IAM role with `PutItem` permissions for the DynamoDB table and associate this role with the Lambda function.

The most secure and recommended way to grant AWS Lambda functions access to other AWS services is by associating an IAM role with the necessary permissions to the Lambda function. This adheres to the principle of least privilege and avoids embedding credentials.

Why the other options are wrong

  • A. Embedding credentials directly is a security anti-pattern and should be avoided in production environments.
  • C. Attaching policies directly to resources for a specific Lambda function is less common and harder to manage than using IAM roles.
  • D. Granting permissions to 'Everyone' is a major security vulnerability and violates the principle of least privilege.

Lambda IAM Role

An IAM role associated with an AWS Lambda function that grants it the necessary permissions to interact with other AWS services.

  • Provides secure access without embedding credentials.
  • Adheres to the principle of least privilege.
  • Managed by IAM policies attached to the role.

Memory trick: Roles are the key to secure Lambda access, protecting your functions from unauthorized calls.

More Development with AWS Services questions