DVA-C02 Development with AWS Services Practice Question
A developer needs to access a DynamoDB table from a Lambda function. The Lambda function is in the same AWS account as the DynamoDB table. What is the most secure way to grant the Lambda function access to the DynamoDB table?
⚠ Common exam trap
Candidates might be tempted by resource-based policies (Option D). While DynamoDB does support resource-based policies, they are primarily used for cross-account access or specific administrative controls. For a Lambda function in the same account, the standard, most secure, and recommended practice is to use the Lambda execution role (identity-based policy).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an IAM role with a policy that grants DynamoDB access and assign it as the Lambda execution role.
The most secure and standard way to grant a Lambda function access to DynamoDB is to create an IAM role with a policy that grants the necessary DynamoDB actions (e.g., dynamodb:GetItem, dynamodb:PutItem) and assign that role as the Lambda execution role. This follows the principle of least privilege and avoids hardcoding credentials, as Lambda automatically assumes this role and manages temporary security credentials. While DynamoDB supports resource-based policies, the Lambda execution role (identity-based policy) remains the standard and recommended approach for granting a Lambda function access to resources within the same account.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use the AWS account root user credentials.
Why it's wrong here
Using the AWS account root user credentials for programmatic access, especially within a Lambda function, is an extremely dangerous security practice. The root user possesses unrestricted administrative access to all resources and services within the entire AWS account. Compromise of these credentials would grant an attacker complete control, violating the fundamental principle of least privilege and posing an unacceptable risk.
- ✗
Store the AWS access key and secret access key in the Lambda environment variables.
Why it's wrong here
Storing AWS access keys and secret access keys directly in Lambda environment variables is an insecure practice that creates a significant vulnerability. These static credentials are long-lived and, if exposed (e.g., through source code repositories, misconfigured logging, or unauthorized access to the Lambda configuration), could grant persistent unauthorized access to the specified AWS resources, making credential rotation and management difficult.
- ✓
Create an IAM role with a policy that grants DynamoDB access and assign it as the Lambda execution role.
Why this is correct
Creating an IAM role with a policy that grants specific DynamoDB access and assigning it as the Lambda execution role is the secure and recommended AWS best practice. This approach provides the Lambda function with temporary, automatically rotated credentials, adhering to the principle of least privilege by allowing access only to the necessary DynamoDB actions and resources without ever exposing static, long-lived credentials.
- ✗
Use a resource-based policy on the DynamoDB table to allow the Lambda function.
Why it's wrong here
DynamoDB tables do not support resource-based policies (also known as access policies) to directly control access from principals like Lambda functions. While some AWS services, such as S3 buckets or SQS queues, utilize resource-based policies, DynamoDB relies exclusively on identity-based policies attached to IAM users or roles to define and manage permissions for accessing its resources.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DVA-C02 question from scratch — 1,135 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.