AWS Certified Developer – Associate (DVA-C02)Development with AWS ServicesHard

A developer is building a serverless application using AWS Lambda and Amazon DynamoDB. The Lambda function needs to perform read and write operations on a DynamoDB table. To adhere to the principle of least privilege, the developer must grant the Lambda function only the necessary permissions. Which IAM policy action should be included to allow the Lambda function to read a single item from a DynamoDB table, given its primary key?

  1. Adynamodb:GetItem
  2. Bdynamodb:Query
  3. Cdynamodb:Scan
  4. Ddynamodb:BatchGetItem
Show answer & explanation

Correct answer: A. dynamodb:GetItem

The 'dynamodb:GetItem' action specifically allows retrieving a single item from a DynamoDB table using its primary key. This aligns with the principle of least privilege by granting only the precise permission required for the operation.

Why the other options are wrong

  • B. dynamodb:Query retrieves items based on a primary key and an optional sort key, typically for multiple items or a range, not a single item by primary key.
  • C. dynamodb:Scan reads all items in a table (or a large portion), which is overly permissive for reading a single item and inefficient.
  • D. dynamodb:BatchGetItem retrieves multiple items from one or more tables, which is more permissive than needed for a single item.

DynamoDB GetItem

The GetItem operation in Amazon DynamoDB retrieves a single item from a table using its primary key.

  • Retrieves a single item.
  • Requires the full primary key.
  • Most efficient way to retrieve specific items.

Memory trick: For a single DynamoDB item, GetItem is the secure rhythm.

More Development with AWS Services questions