SCS-C02 Identity and Access Management Practice Question
A security team wants to grant a Lambda function access to read from a DynamoDB table in the same account. What is the most secure way to do this?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an IAM role with a policy that allows only the required DynamoDB actions (e.g., GetItem, Query) on the specific table and assign it to the Lambda function.
The most secure method is D because it follows the principle of least privilege by creating a custom IAM role that grants only the necessary DynamoDB actions (like GetItem, Query) on the specific table. This limits the Lambda function's permissions to only what is required. Option A is incorrect because a VPC endpoint allows network access to DynamoDB but does not grant IAM permissions; the Lambda function still needs an IAM role with appropriate permissions. Option B is incorrect because attaching the managed policy AmazonDynamoDBFullAccess grants full access to all DynamoDB resources, violating least privilege and increasing security risk. Option C is incorrect because storing database access keys in Lambda environment variables exposes credentials and is insecure; the recommended approach is to use an IAM execution role.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a VPC endpoint for DynamoDB and associate it with the Lambda function.
Why it's wrong here
A VPC endpoint for DynamoDB only establishes a private network path between your VPC and the DynamoDB service, bypassing the public internet. It does not, by itself, grant the Lambda execution role any permission to perform DynamoDB actions; IAM authorization is still enforced on every API call. Even if you attach the endpoint to the Lambda function's VPC configuration, the function's role must explicitly allow actions like GetItem or Query on the table — otherwise the call fails with an AccessDenied error.
- ✗
Attach the AWS managed policy AmazonDynamoDBFullAccess to the Lambda execution role.
Why it's wrong here
AmazonDynamoDBFullAccess is an AWS managed policy that grants full administrative and data-plane access to all DynamoDB resources, including CreateTable, DeleteTable, Scan, and DeleteItem on any table in the account. Attaching it to the Lambda execution role violates the principle of least privilege, which is a fundamental security best practice and often a compliance requirement. If the Lambda function is compromised, an attacker could use these excessive permissions to delete or exfiltrate data from unrelated tables. A scoped custom policy should be used instead, allowing only the specific actions on the specific table.
- ✗
Store the database access keys in the Lambda environment variables.
Why it's wrong here
Storing database access keys in Lambda environment variables is insecure because it hard-codes long-term credentials that do not rotate automatically. These keys could be exposed through the Lambda console, environment variable retrieval APIs, or CloudWatch Logs if the function logs its configuration. Additionally, AWS Lambda already uses an execution role to obtain temporary security credentials via the instance/role credential provider chain, making long-term access keys unnecessary and counterproductive. This approach also breaks the recommended practice of using IAM roles for AWS service-to-service access.
- ✓
Create an IAM role with a policy that allows only the required DynamoDB actions (e.g., GetItem, Query) on the specific table and assign it to the Lambda function.
Why this is correct
The correct approach is to create a custom IAM role with a policy that grants only the required DynamoDB actions (e.g., GetItem, Query) on the specific table ARN, and then assign that role to the Lambda function as its execution role. At runtime, Lambda uses this role to obtain temporary credentials through AWS STS, which are automatically rotated and scoped to the policy. This follows the principle of least privilege because the function can only perform the exact actions on the exact table it needs, minimizing the blast radius of a compromise. It is the AWS-recommended best practice for granting Lambda functions access to AWS services.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.