CompTIA Cloud+ (CV0-004)SecurityHard
A cloud security specialist is hardening a serverless application that uses AWS Lambda functions and API Gateway. The team needs to ensure that Lambda functions can only be invoked by the specific API Gateway instance associated with the application, preventing unauthorized invocation from other sources or accounts. Which security measure should be implemented?
- AImplement a VPC endpoint for Lambda to restrict access to internal VPC traffic.
- BApply an IAM role to the Lambda function with restricted invocation permissions.
- CUtilize AWS WAF with API Gateway to filter incoming requests.
- DConfigure the Lambda function's resource-based policy to allow invocation only from the specific API Gateway ARN.
Show answer & explanationAnswer & explanation
Correct answer: D. Configure the Lambda function's resource-based policy to allow invocation only from the specific API Gateway ARN.
A resource-based policy (also known as a Lambda permission policy) attached directly to the Lambda function is the correct mechanism to control which AWS services or accounts can invoke it. By specifying the exact API Gateway ARN as the principal in the policy, unauthorized invocations are prevented.
Why the other options are wrong
- A. A VPC endpoint for Lambda allows functions to access resources within a VPC privately, or for resources within a VPC to invoke Lambda. It doesn't prevent external API Gateway invocation or restrict which *specific* API Gateway can invoke it.
- B. An IAM role attached to the Lambda function defines *what the Lambda function can do* (its execution permissions), not *who or what can invoke the Lambda function* (its invocation permissions). These are distinct concepts.
- C. AWS WAF with API Gateway filters HTTP requests based on web attack patterns and rules, but it doesn't control the invocation permissions of the downstream Lambda function itself.
Lambda Resource-Based Policy
A policy attached directly to an AWS Lambda function that defines which principals (users, roles, AWS services) can invoke or access the function.
- Controls invocation permissions.
- Uses JSON policy syntax.
- Managed directly on the Lambda function.
Memory trick: Lambda's policy is its bouncer.