Courseiva

DVA-C02 Development with AWS Services Practice Question

A company is designing a microservices architecture using AWS Lambda. Each microservice has its own DynamoDB table. The Lambda functions need to perform CRUD operations on their respective tables. Which TWO IAM best practices should be applied? (Choose TWO.)

⚠ Common exam trap

A common mix-up: candidates think a single shared role simplifies management (Option B) or that wildcards are acceptable for convenience (Option A), overlooking the critical security requirement for least privilege in microservices.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Scope the IAM policy resource to the specific DynamoDB table ARN.

Scoping the IAM policy resource to the specific DynamoDB table ARN follows the principle of least privilege, ensuring each Lambda function can only access its own table. Option E is correct because creating a separate IAM role for each Lambda function isolates permissions, preventing a compromised function from affecting others. Together, these practices enforce granular access control in a microservices architecture.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Grant access to all DynamoDB tables using a wildcard in the resource ARN.

    Why it's wrong here

    Granting access to all DynamoDB tables using a wildcard (e.g., `arn:aws:dynamodb:*:*:table/*`) in the resource ARN is a severe security misconfiguration. This approach directly violates the principle of least privilege by providing a Lambda function access to every table in the account, even those it doesn't need. Such broad permissions significantly increase the attack surface and potential impact if the Lambda function or its execution role is compromised, making it an unacceptable practice.

  • ✗

    Use a single IAM role shared by all Lambda functions.

    Why it's wrong here

    Using a single IAM role shared by all Lambda functions in a microservices architecture directly violates the principle of least privilege. Each microservice typically has distinct resource access requirements, and a shared role would necessitate granting the union of all permissions to every function. This over-privileging means a function could potentially access resources it should not, creating unnecessary security risks and making auditing difficult and less effective.

  • ✗

    Attach the IAM policy to the AWS account instead of the role.

    Why it's wrong here

    Attaching an IAM policy directly to the AWS account is not a recommended security practice for managing permissions for specific services or applications. Account-level policies, such as Service Control Policies (SCPs) in AWS Organizations, are typically used for guardrails across Organizational Units, not for granting specific runtime permissions to individual resources like Lambda functions. For fine-grained control and adherence to least privilege, policies should always be attached to IAM roles or users, which are then assumed by services or individuals.

  • ✓

    Scope the IAM policy resource to the specific DynamoDB table ARN.

    Why this is correct

    Scoping the IAM policy resource to the specific DynamoDB table ARN (e.g., `arn:aws:dynamodb:region:account-id:table/TableName`) is a fundamental best practice for enforcing the principle of least privilege. This ensures that the Lambda function's execution role only has permissions to interact with the exact DynamoDB table it requires for its operations. This precise resource definition minimizes the potential blast radius of a security incident, as unauthorized access would be confined to only the explicitly allowed resource.

  • ✓

    Create a separate IAM role for each Lambda function.

    Why this is correct

    Creating a separate IAM role for each Lambda function is a cornerstone of a secure microservices architecture, directly enforcing the principle of least privilege at a granular level. Each function can then be assigned a role with only the precise permissions it needs to perform its specific task, such as reading from one S3 bucket and writing to a particular DynamoDB table. This isolation prevents a compromised function from gaining unauthorized access to resources intended for other services.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.