DVA-C02 Security Practice Question
A Lambda function needs to read from a DynamoDB table and send messages to an SQS queue. The function's IAM role should follow the principle of least privilege. Which policy statement should be attached to the role?
⚠ Common exam trap
Watch out — candidates often choose a wildcard resource or overly broad actions (like dynamodb:* or sqs:*) because they think it's simpler, failing to recognize that the principle of least privilege requires scoping both actions and resources to the minimum necessary.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
{"Effect":"Allow","Action":["dynamodb:GetItem"],"Resource":"arn:aws:dynamodb:us-east-1:123456789012:table/MyTable"}, {"Effect":"Allow","Action":["sqs:SendMessage"],"Resource":"arn:aws:sqs:us-east-1:123456789012:MyQueue"}
It grants only the specific DynamoDB read action (GetItem) needed to read from the table and the specific SQS write action (SendMessage) needed to send messages to the queue, scoped to the exact resource ARNs. This adheres to the principle of least privilege by not allowing any unnecessary operations or resources. Wrapping the statements in an array makes the policy snippet syntactically valid.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
{"Effect":"Allow","Action":["dynamodb:*"],"Resource":"arn:aws:dynamodb:us-east-1:123456789012:table/MyTable"}
Why it's wrong here
The "dynamodb:*" action grants full administrative access to the specified DynamoDB table, including PutItem, UpdateItem, DeleteItem, and CreateTable, which far exceeds the requirement to merely read data. This violates the principle of least privilege by providing unnecessary write and management capabilities. Furthermore, this policy completely omits the required SQS SendMessage permission, making it insufficient for the function's full scope.
- ✓
{"Effect":"Allow","Action":["dynamodb:GetItem"],"Resource":"arn:aws:dynamodb:us-east-1:123456789012:table/MyTable"}, {"Effect":"Allow","Action":["sqs:SendMessage"],"Resource":"arn:aws:sqs:us-east-1:123456789012:MyQueue"}
Why this is correct
This policy correctly applies the principle of least privilege by granting only the "dynamodb:GetItem" action, which is necessary for reading data from the specified DynamoDB table. Additionally, it provides the "sqs:SendMessage" action, which is precisely what the Lambda function requires to interact with the designated SQS queue. Each permission is scoped to its specific resource, ensuring minimal access.
- ✗
{"Effect":"Allow","Action":["dynamodb:GetItem","sqs:SendMessage","sqs:ReceiveMessage"],"Resource":"*"}
Why it's wrong here
While "dynamodb:GetItem" and "sqs:SendMessage" are appropriate actions, this policy incorrectly includes "sqs:ReceiveMessage", which is not required for a Lambda function that only sends messages to SQS. More critically, specifying "Resource: "*"" grants these permissions across *all* DynamoDB tables and SQS queues in the account, a significant security vulnerability that violates least privilege by allowing access to unauthorized resources.
- ✗
{"Effect":"Allow","Action":["dynamodb:GetItem","dynamodb:PutItem"],"Resource":"*"}
Why it's wrong here
This policy is flawed because it includes "dynamodb:PutItem", an action for writing data, when the requirement is only to read from DynamoDB. This violates the principle of least privilege. Furthermore, it completely omits the necessary "sqs:SendMessage" permission, making the policy incomplete for the function's stated purpose. The "Resource: "*"" also grants access to all DynamoDB tables, which is overly permissive.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
This DVA-C02 question is part of Courseiva's 1,135-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.