Courseiva
Security →hardMultiple Choice

DVA-C02 Security Practice Question

A Lambda function needs to read from a DynamoDB table and send messages to an SQS queue. The function's IAM role should follow the principle of least privilege. Which policy statement should be attached to the role?

⚠ Common exam trap

Watch out — candidates often choose a wildcard resource or overly broad actions (like dynamodb:* or sqs:*) because they think it's simpler, failing to recognize that the principle of least privilege requires scoping both actions and resources to the minimum necessary.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

{"Effect":"Allow","Action":["dynamodb:GetItem"],"Resource":"arn:aws:dynamodb:us-east-1:123456789012:table/MyTable"}, {"Effect":"Allow","Action":["sqs:SendMessage"],"Resource":"arn:aws:sqs:us-east-1:123456789012:MyQueue"}

It grants only the specific DynamoDB read action (GetItem) needed to read from the table and the specific SQS write action (SendMessage) needed to send messages to the queue, scoped to the exact resource ARNs. This adheres to the principle of least privilege by not allowing any unnecessary operations or resources. Wrapping the statements in an array makes the policy snippet syntactically valid.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    {"Effect":"Allow","Action":["dynamodb:*"],"Resource":"arn:aws:dynamodb:us-east-1:123456789012:table/MyTable"}

    Why it's wrong here

    The "dynamodb:*" action grants full administrative access to the specified DynamoDB table, including PutItem, UpdateItem, DeleteItem, and CreateTable, which far exceeds the requirement to merely read data. This violates the principle of least privilege by providing unnecessary write and management capabilities. Furthermore, this policy completely omits the required SQS SendMessage permission, making it insufficient for the function's full scope.

  • ✓

    {"Effect":"Allow","Action":["dynamodb:GetItem"],"Resource":"arn:aws:dynamodb:us-east-1:123456789012:table/MyTable"}, {"Effect":"Allow","Action":["sqs:SendMessage"],"Resource":"arn:aws:sqs:us-east-1:123456789012:MyQueue"}

    Why this is correct

    This policy correctly applies the principle of least privilege by granting only the "dynamodb:GetItem" action, which is necessary for reading data from the specified DynamoDB table. Additionally, it provides the "sqs:SendMessage" action, which is precisely what the Lambda function requires to interact with the designated SQS queue. Each permission is scoped to its specific resource, ensuring minimal access.

  • ✗

    {"Effect":"Allow","Action":["dynamodb:GetItem","sqs:SendMessage","sqs:ReceiveMessage"],"Resource":"*"}

    Why it's wrong here

    While "dynamodb:GetItem" and "sqs:SendMessage" are appropriate actions, this policy incorrectly includes "sqs:ReceiveMessage", which is not required for a Lambda function that only sends messages to SQS. More critically, specifying "Resource: "*"" grants these permissions across *all* DynamoDB tables and SQS queues in the account, a significant security vulnerability that violates least privilege by allowing access to unauthorized resources.

  • ✗

    {"Effect":"Allow","Action":["dynamodb:GetItem","dynamodb:PutItem"],"Resource":"*"}

    Why it's wrong here

    This policy is flawed because it includes "dynamodb:PutItem", an action for writing data, when the requirement is only to read from DynamoDB. This violates the principle of least privilege. Furthermore, it completely omits the necessary "sqs:SendMessage" permission, making the policy incomplete for the function's stated purpose. The "Resource: "*"" also grants access to all DynamoDB tables, which is overly permissive.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

This DVA-C02 question is part of Courseiva's 1,135-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.