AWS Certified Developer – Associate (DVA-C02)SecurityHard

A developer is building a mobile application that needs to securely store user-specific data (e.g., application settings, high scores) in the cloud. Each user should only be able to read and write their own data. The application uses Amazon Cognito for user authentication. Which AWS service, combined with Cognito, is the MOST appropriate for storing this user-specific data with granular access control?

  1. AAmazon DynamoDB with IAM policies that leverage Cognito Identity Pool variables.
  2. BAmazon RDS with a separate table for each user.
  3. CAmazon S3 with bucket policies based on Cognito user IDs.
  4. DAWS Systems Manager Parameter Store to store user data as parameters.
Show answer & explanation

Correct answer: A. Amazon DynamoDB with IAM policies that leverage Cognito Identity Pool variables.

DynamoDB is a highly scalable NoSQL database ideal for user-specific data. When combined with Cognito Identity Pools, you can use IAM policies that leverage variables like `cognito-identity.amazonaws.com:sub` (the user's unique identity ID) to grant each authenticated user read/write access ONLY to items in a DynamoDB table where the partition key matches their identity ID, achieving granular, user-specific access.

Why the other options are wrong

  • B. Using a separate RDS table for each user is not scalable, cost-effective, or manageable for a mobile application with many users.
  • C. While S3 can store user data, DynamoDB is often a better fit for structured user settings/scores. S3 bucket policies for per-user access are possible but often more complex to manage at a granular level than DynamoDB IAM policies for item-level access.
  • D. Parameter Store is for application configuration, not for storing large volumes of user-specific data.

DynamoDB with Cognito for User Data

Amazon DynamoDB combined with Amazon Cognito Identity Pools provides a scalable solution for storing user-specific data with fine-grained access control. IAM policies use Cognito Identity Pool variables to restrict users to their own data.

  • Cognito Identity Pools federate authenticated users to AWS.
  • IAM policies use `cognito-identity.amazonaws.com:sub` (identity ID) for resource-level access.
  • DynamoDB table's primary key (e.g., partition key) often matches the user's identity ID.
  • Enables each user to read/write only their own data.

Memory trick: Cognito grants the ID, DynamoDB stores the data, IAM policy keeps it separate.

More Security questions