AWS Certified Developer – Associate (DVA-C02)SecurityHard

A developer is building a mobile application that needs to securely store user-specific data in a NoSQL database. Each user should only be able to access and modify their own data. The application uses Amazon Cognito for user authentication. Which AWS service and configuration should the developer use to store this data while enforcing fine-grained access control based on the authenticated user?

  1. AAmazon RDS with row-level security and a custom authorization layer.
  2. BAmazon DynamoDB with IAM policies and fine-grained access control using Amazon Cognito Identity Pools.
  3. CAWS AppSync with GraphQL resolvers and Lambda authorizers.
  4. DAmazon S3 with bucket policies filtering by Cognito user ID.
Show answer & explanation

Correct answer: B. Amazon DynamoDB with IAM policies and fine-grained access control using Amazon Cognito Identity Pools.

Amazon Cognito Identity Pools can federate authenticated users to AWS, providing temporary credentials linked to an IAM role. This IAM role can then have policies with conditions that restrict access to DynamoDB items based on the Cognito user ID, providing fine-grained, user-specific access control.

Why the other options are wrong

  • A. RDS is a relational database, not typically the first choice for 'NoSQL database' requirements, and implementing row-level security with a custom authorization layer is more complex than DynamoDB's native integration.
  • C. AppSync can facilitate data access but requires DynamoDB as a backend. The core mechanism for fine-grained user-specific access to DynamoDB directly relies on IAM policies and Cognito Identity Pools.
  • D. While S3 can store data, DynamoDB is a NoSQL database, and while S3 bucket policies can filter, DynamoDB's fine-grained access with Cognito is more suitable for structured user data.

DynamoDB Fine-Grained Access with Cognito

Amazon DynamoDB can enforce fine-grained access control for user-specific data by combining IAM policies with attributes provided by Amazon Cognito Identity Pools, such as the authenticated user's ID.

  • Cognito Identity Pools provide temporary AWS credentials.
  • IAM policies attached to the Identity Pool role can use conditions.
  • Conditions can restrict DynamoDB item access based on user ID or other attributes.

Memory trick: Cognito with IAM Secures DynamoDB Data.

More Security questions