CompTIA Security+ (SY0-701)Security ArchitectureMedium
A developer writes a serverless function that is triggered whenever a file is uploaded to a storage bucket. During a review, a security engineer notices the function's execution role has full administrative permissions across the entire cloud account. Which principle is being violated?
- ALeast privilege
- BSeparation of duties
- CZero trust segmentation
- DDefense in depth
Show answer & explanationAnswer & explanation
Correct answer: A. Least privilege
Least privilege requires that a serverless function's execution role be scoped only to the specific resources and actions it needs (e.g., read/write to one bucket), not full account-wide admin rights.
Why the other options are wrong
- B. Separation of duties concerns dividing tasks among multiple people/roles to prevent fraud.
- C. Zero trust segmentation refers to continuous verification and micro-segmentation, not permission scope directly.
- D. Defense in depth is about layered controls, not the scope of a single role's permissions.
Least Privilege (Serverless)
The principle that a function, service, or user should be granted only the minimum permissions required to perform its task.
- Overly broad IAM roles on serverless functions are a top cloud misconfiguration risk
- Scope roles to specific resources/actions (e.g., s3:GetObject on one bucket)
- Reduces blast radius if the function is compromised
Memory trick: 'Give the function a single key, not the master keyring.'