CompTIA Security+ (SY0-701)Security ArchitectureMedium

A developer writes a serverless function that is triggered whenever a file is uploaded to a storage bucket. During a review, a security engineer notices the function's execution role has full administrative permissions across the entire cloud account. Which principle is being violated?

  1. ALeast privilege
  2. BSeparation of duties
  3. CZero trust segmentation
  4. DDefense in depth
Show answer & explanation

Correct answer: A. Least privilege

Least privilege requires that a serverless function's execution role be scoped only to the specific resources and actions it needs (e.g., read/write to one bucket), not full account-wide admin rights.

Why the other options are wrong

  • B. Separation of duties concerns dividing tasks among multiple people/roles to prevent fraud.
  • C. Zero trust segmentation refers to continuous verification and micro-segmentation, not permission scope directly.
  • D. Defense in depth is about layered controls, not the scope of a single role's permissions.

Least Privilege (Serverless)

The principle that a function, service, or user should be granted only the minimum permissions required to perform its task.

  • Overly broad IAM roles on serverless functions are a top cloud misconfiguration risk
  • Scope roles to specific resources/actions (e.g., s3:GetObject on one bucket)
  • Reduces blast radius if the function is compromised

Memory trick: 'Give the function a single key, not the master keyring.'

More Security Architecture questions