Courseiva

SCS-C02 Identity and Access Management Practice Question

A developer is creating an AWS Lambda function that needs to read items from a DynamoDB table. The function is deployed in a VPC with no internet access. What is the MOST secure way to grant the Lambda function access to DynamoDB?

⚠ Common exam trap

The trap is thinking that a resource-based policy on DynamoDB or an API Gateway integration is needed, when the correct solution is a VPC endpoint combined with an IAM execution role; candidates might also incorrectly assume that Lambda functions can have public IPs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a VPC endpoint for DynamoDB and attach an IAM execution role to the Lambda function with the necessary permissions.

A VPC endpoint for DynamoDB allows private connectivity from within a VPC to DynamoDB without requiring an internet gateway, NAT device, or VPN. Attaching an IAM execution role to the Lambda function with the necessary DynamoDB permissions grants the function the required access. This combination is the most secure because it keeps traffic within the AWS network and uses least privilege.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Attach a public IP to the Lambda function and use an IAM role with DynamoDB permissions.

    Why it's wrong here

    Attaching a public IP to a Lambda function is not a supported operation; AWS Lambda only assigns private IPs from the VPC subnet to its hyperplane ENIs, and those functions have no direct route to the internet even if an IAM role trusts them. DynamoDB's public endpoint is only reachable via a NAT gateway/NAT instance or a VPC endpoint, so merely pairing a public IP with DynamoDB permissions would not establish connectivity. IAM authorizes the API calls, but it does not create a network path when the function is isolated in a private subnet.

  • ✗

    Create an API Gateway REST API with a VPC link and DynamoDB integration.

    Why it's wrong here

    An API Gateway REST API with a VPC link is designed to route requests to private resources behind an Application or Network Load Balancer inside a VPC, not to AWS managed services like DynamoDB. To have API Gateway call DynamoDB directly, you would use an AWS service integration with a role that allows the API to invoke DynamoDB, completely bypassing Lambda. Adding Lambda to this flow would require writing a custom integration or proxy, so the VPC link adds irrelevant networking complexity and does not solve the Lambda-to-DynamoDB access requirement.

  • ✗

    Use a resource-based policy on the DynamoDB table allowing access from the Lambda function's ARN.

    Why it's wrong here

    DynamoDB is an AWS managed service that uses IAM identity-based policies on the principal (the Lambda execution role) to control access; it does not accept resource-based policies akin to an S3 bucket policy. A resource-based policy cannot be attached to a table to whitelist a Lambda function's ARN, and even if it could, such an IAM mechanism would only authorize requests—it would not provide the missing network path if the Lambda is VPC-isolated. Permissions for DynamoDB actions such as GetItem and PutItem must be attached to the IAM role that the function assumes at runtime.

  • ✓

    Create a VPC endpoint for DynamoDB and attach an IAM execution role to the Lambda function with the necessary permissions.

    Why this is correct

    Creating a gateway VPC endpoint for DynamoDB gives the Lambda function's subnet a private route to the DynamoDB service, avoiding the public internet and any need for a NAT gateway. The Lambda execution role should carry an identity policy with the specific DynamoDB actions and resource (table ARN) so the function is both network-reachable and authorized to perform the operation. This combines the correct network path with the correct IAM authorization, and the endpoint works through a route-table prefix list rather than an ENI in the function's subnet.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.