CompTIA SecurityX (CAS-005)Security OperationsMedium

A security architect is designing a new cloud-native application that will handle highly sensitive customer data. The application will leverage serverless functions (AWS Lambda) and a managed NoSQL database (DynamoDB). To minimize the attack surface and ensure data integrity, which security principle should be most rigorously applied to the serverless functions' permissions?

  1. ALeast privilege
  2. BFail-safe defaults
  3. CSeparation of duties
  4. DDefense in depth
Show answer & explanation

Correct answer: A. Least privilege

Least privilege mandates that a subject (in this case, a serverless function) should be granted only the minimum necessary permissions to perform its intended function. For highly sensitive data and serverless functions, this is critical to prevent a compromised function from accessing or manipulating data it shouldn't. While other principles are important, least privilege directly addresses the permissions to sensitive data.

Why the other options are wrong

  • B. Fail-safe defaults ensure secure settings by default, but least privilege defines *what* those secure settings should be for permissions.
  • C. Separation of duties applies to human roles and responsibilities, not directly to function permissions.
  • D. Defense in depth is a general strategy, not a specific principle for function permissions.

Principle of Least Privilege

A security principle that requires that a subject (user, process, program, or function) be given only the minimum set of permissions necessary to perform its legitimate tasks. This limits the potential damage if that subject is compromised.

  • Grants only essential permissions.
  • Limits impact of compromise.
  • Crucial for sensitive data and serverless environments.

Memory trick: Serverless Functions Need the Least Privilege to Shine.

More Security Operations questions