AWS Certified Developer – Associate (DVA-C02)SecurityHard

A developer is building a mobile application that needs to securely store user-specific data in an Amazon DynamoDB table. Each user should only be able to access and modify their own data, and no other user's data. The application uses Amazon Cognito for user authentication. How can the developer implement this fine-grained access control for DynamoDB?

  1. AStore user data in separate DynamoDB tables for each user and grant access based on table name.
  2. BUse an IAM policy with DynamoDB conditions that reference the Cognito User Pool ID.
  3. CImplement a Lambda authorizer for all DynamoDB operations to validate user ownership.
  4. DConfigure an IAM role in an Amazon Cognito Identity Pool, with a policy that uses `cognito-identity.amazonaws.com:sub` as a condition key to restrict access.
Show answer & explanation

Correct answer: D. Configure an IAM role in an Amazon Cognito Identity Pool, with a policy that uses `cognito-identity.amazonaws.com:sub` as a condition key to restrict access.

Using an IAM role configured within a Cognito Identity Pool, with a policy that includes `cognito-identity.amazonaws.com:sub` as a condition key, effectively restricts DynamoDB access to only the data owned by the authenticated user's unique Cognito ID. This is the recommended and most scalable approach for fine-grained access.

Why the other options are wrong

  • A. Creating separate tables for each user is highly inefficient, unscalable, and costly for a large number of users, and is not a practical solution for fine-grained access control.
  • B. While IAM policies are used, simply referencing the Cognito User Pool ID is not granular enough to restrict access to *individual user's* data. It would grant access to anyone from that pool.
  • C. A Lambda authorizer is primarily for API Gateway authorization, not for direct fine-grained access control on DynamoDB. While a Lambda could proxy DynamoDB, it adds complexity and cost, and misses the direct IAM policy approach.

DynamoDB Fine-Grained Access with Cognito

Achieve fine-grained access control for DynamoDB items based on authenticated users from Amazon Cognito Identity Pools. IAM policies leverage the `cognito-identity.amazonaws.com:sub` context key to restrict access to items where the user's ID matches an attribute in the item.

  • Uses Cognito Identity Pools.
  • IAM policy with condition key `cognito-identity.amazonaws.com:sub`.
  • Restricts users to their own data.
  • Scalable and secure.

Memory trick: Cognito Identity Pools and IAM 'sub' condition keys lock down DynamoDB to each user's data.

More Security questions