AWS Certified Developer – Associate (DVA-C02)Development with AWS ServicesMedium

A developer is writing an AWS Lambda function that needs to interact with Amazon DynamoDB. The function requires permissions to perform 'PutItem' and 'UpdateItem' actions on a specific DynamoDB table named 'ProductCatalog'. Which of the following IAM policy statements should be attached to the Lambda function's execution role to grant the MINIMUM necessary permissions?

  1. A{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": ["dynamodb:PutItem", "dynamodb:UpdateItem"], "Resource": "arn:aws:dynamodb:REGION:ACCOUNT_ID:table/*" } ] }
  2. B{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": ["dynamodb:PutItem", "dynamodb:UpdateItem"], "Resource": "arn:aws:dynamodb:REGION:ACCOUNT_ID:table/ProductCatalog" } ] }
  3. C{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": ["dynamodb:*"], "Resource": "arn:aws:dynamodb:REGION:ACCOUNT_ID:table/ProductCatalog" } ] }
  4. D{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": ["dynamodb:PutItem", "dynamodb:UpdateItem"], "Resource": "*" } ] }
Show answer & explanation

Correct answer: B. { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": ["dynamodb:PutItem", "dynamodb:UpdateItem"], "Resource": "arn:aws:dynamodb:REGION:ACCOUNT_ID:table/ProductCatalog" } ] }

To follow the principle of least privilege, the IAM policy should explicitly list only the required actions ('PutItem', 'UpdateItem') and restrict the resource to the specific DynamoDB table ('ProductCatalog').

Why the other options are wrong

  • A. This policy grants the specified actions on all tables ('table/*') within the account, which is too broad if only one table is needed.
  • C. This policy grants 'dynamodb:*' (all actions) which violates the principle of least privilege.
  • D. This policy grants the specified actions on all DynamoDB resources ('*'), which is too broad and violates the principle of least privilege.

Principle of Least Privilege

A security best practice where users, programs, and processes are given only the minimum privileges necessary to perform their work.

  • Reduces the attack surface.
  • Limits the blast radius in case of compromise.
  • Applies to actions and resources in IAM policies.

Memory trick: Only the precise key for the exact lock, nothing more.

More Development with AWS Services questions