A developer is using AWS SAM to define a serverless application. The application includes an AWS Lambda function that needs to access an Amazon DynamoDB table. The developer wants to grant the Lambda function the minimum required permissions to read and write items in the table. Which resource should the developer use to define the IAM permissions?
The Policies property within an AWS::Serverless::Function resource in a SAM template is the designated and most efficient way to attach IAM permissions to the Lambda function's execution role. This property allows developers to specify predefined SAM policy templates (e.g., DynamoDBReadPolicy) or define custom inline IAM policy statements, granting the function the necessary permissions to interact with other AWS services like DynamoDB. It directly modifies the function's execution role to allow specific actions.
Why this answer
The AWS::Serverless::Function resource's Policies property allows you to attach IAM policies directly to the Lambda function's execution role in a declarative manner. By specifying a policy statement with dynamodb:GetItem, dynamodb:PutItem, etc., and the ARN of the DynamoDB table, you grant the minimum required permissions for read and write access without manually creating an IAM role. SAM automatically creates and associates the IAM role with the function, simplifying permission management.
Exam trap
The trap here is that candidates confuse AWS::Lambda::Permission (which controls who can invoke the Lambda) with the IAM permissions needed for the Lambda to access other services, leading them to select Option D instead of the correct Policies property.
How to eliminate wrong answers
Option A is wrong because AWS::DynamoDB::Table defines the DynamoDB table resource itself, not IAM permissions; it cannot grant access to Lambda functions. Option B is wrong because AWS::IAM::Role is a generic CloudFormation resource that requires you to manually define the role, trust policy, and attach policies, which is more verbose and error-prone than using SAM's Policies property. Option D is wrong because AWS::Lambda::Permission is used to grant other AWS services or accounts permission to invoke the Lambda function, not to grant the Lambda function permissions to access other resources like DynamoDB.