Courseiva

SCS-C02 Identity and Access Management Practice Question

A security team wants to grant a Lambda function access to read from a DynamoDB table in the same account. What is the most secure way to do this?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an IAM role with a policy that allows only the required DynamoDB actions (e.g., GetItem, Query) on the specific table and assign it to the Lambda function.

The most secure method is D because it follows the principle of least privilege by creating a custom IAM role that grants only the necessary DynamoDB actions (like GetItem, Query) on the specific table. This limits the Lambda function's permissions to only what is required. Option A is incorrect because a VPC endpoint allows network access to DynamoDB but does not grant IAM permissions; the Lambda function still needs an IAM role with appropriate permissions. Option B is incorrect because attaching the managed policy AmazonDynamoDBFullAccess grants full access to all DynamoDB resources, violating least privilege and increasing security risk. Option C is incorrect because storing database access keys in Lambda environment variables exposes credentials and is insecure; the recommended approach is to use an IAM execution role.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a VPC endpoint for DynamoDB and associate it with the Lambda function.

    Why it's wrong here

    A VPC endpoint for DynamoDB only establishes a private network path between your VPC and the DynamoDB service, bypassing the public internet. It does not, by itself, grant the Lambda execution role any permission to perform DynamoDB actions; IAM authorization is still enforced on every API call. Even if you attach the endpoint to the Lambda function's VPC configuration, the function's role must explicitly allow actions like GetItem or Query on the table — otherwise the call fails with an AccessDenied error.

  • ✗

    Attach the AWS managed policy AmazonDynamoDBFullAccess to the Lambda execution role.

    Why it's wrong here

    AmazonDynamoDBFullAccess is an AWS managed policy that grants full administrative and data-plane access to all DynamoDB resources, including CreateTable, DeleteTable, Scan, and DeleteItem on any table in the account. Attaching it to the Lambda execution role violates the principle of least privilege, which is a fundamental security best practice and often a compliance requirement. If the Lambda function is compromised, an attacker could use these excessive permissions to delete or exfiltrate data from unrelated tables. A scoped custom policy should be used instead, allowing only the specific actions on the specific table.

  • ✗

    Store the database access keys in the Lambda environment variables.

    Why it's wrong here

    Storing database access keys in Lambda environment variables is insecure because it hard-codes long-term credentials that do not rotate automatically. These keys could be exposed through the Lambda console, environment variable retrieval APIs, or CloudWatch Logs if the function logs its configuration. Additionally, AWS Lambda already uses an execution role to obtain temporary security credentials via the instance/role credential provider chain, making long-term access keys unnecessary and counterproductive. This approach also breaks the recommended practice of using IAM roles for AWS service-to-service access.

  • ✓

    Create an IAM role with a policy that allows only the required DynamoDB actions (e.g., GetItem, Query) on the specific table and assign it to the Lambda function.

    Why this is correct

    The correct approach is to create a custom IAM role with a policy that grants only the required DynamoDB actions (e.g., GetItem, Query) on the specific table ARN, and then assign that role to the Lambda function as its execution role. At runtime, Lambda uses this role to obtain temporary credentials through AWS STS, which are automatically rotated and scoped to the policy. This follows the principle of least privilege because the function can only perform the exact actions on the exact table it needs, minimizing the blast radius of a compromise. It is the AWS-recommended best practice for granting Lambda functions access to AWS services.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.