A developer is building a serverless application using AWS Lambda to process files uploaded to an S3 bucket. The Lambda function needs to read the uploaded file, transform it, and write the result to a DynamoDB table. Which IAM policy statement should be attached to the Lambda execution role?
s3:GetObject correctly grants permission to download the uploaded file's bytes from the S3 bucket for processing, and dynamodb:PutItem correctly grants permission to insert or overwrite the transformed result as a new item, which matches the function's actual read-from-S3, write-to-DynamoDB data flow exactly.
Why this answer
The Lambda function needs to read the uploaded file from S3 (requiring s3:GetObject) and write the transformed result to DynamoDB (requiring dynamodb:PutItem). Option A correctly grants both actions with a wildcard resource, which is acceptable for a learning scenario but should be scoped in production. This matches the exact permissions needed for the described workflow.
Exam trap
The trap here is confusing the direction of data flow: candidates mistakenly choose write permissions for S3 (s3:PutObject) or read permissions for DynamoDB (dynamodb:GetItem), failing to map the correct action to each service based on whether data is being read from or written to that service.
How to eliminate wrong answers
Option B is wrong because it grants s3:PutObject (write to S3) instead of s3:GetObject (read from S3); the Lambda only reads the uploaded file, not writes back to S3. Option C is wrong because it grants dynamodb:UpdateItem (modify an existing item) instead of dynamodb:PutItem (create a new item); the requirement is to write the result, which implies inserting a new record, not updating an existing one. Option D is wrong because it grants dynamodb:GetItem (read from DynamoDB) instead of dynamodb:PutItem; the Lambda writes to DynamoDB, not reads from it.