CompTIA Cloud+ (CV0-004)SecurityMedium

A cloud security professional is reviewing the access policies for a critical serverless function that processes financial transactions. The function currently has broad permissions, including access to several object storage buckets and a database, which violates the principle of least privilege. Which IAM concept should be applied to restrict the function's permissions to only the specific resources and actions it absolutely needs?

  1. ATime-Based Access Control
  2. BAttribute-Based Access Control (ABAC)
  3. CRole-Based Access Control (RBAC)
  4. DResource-Based Policy
Show answer & explanation

Correct answer: D. Resource-Based Policy

For serverless functions, a Resource-Based Policy (often referred to as a resource policy in AWS Lambda or similar services) is typically attached directly to the resource itself (the Lambda function in this case). This policy explicitly defines who can access the resource and what actions they can perform on it, allowing for fine-grained control and adherence to the principle of least privilege for the function's interactions with other services.

Why the other options are wrong

  • A. Time-Based Access Control restricts access based on time, not the type of resource or action.
  • B. ABAC grants permissions based on attributes, which is more dynamic but not the primary mechanism for restricting a function's direct resource access.
  • C. RBAC assigns permissions based on job function, but a resource-based policy provides more granular control for a specific function's needs.

Resource-Based Policy (Serverless)

A policy attached directly to a cloud resource (like a serverless function, S3 bucket, or SQS queue) that specifies which principals (users, roles, other services) have permissions to access that resource and what actions they can perform.

  • Attached directly to the resource.
  • Defines permissions 'on' the resource.
  • Often used in conjunction with identity-based policies.
  • Crucial for cross-account access and service-to-service permissions.
  • Enforces the principle of least privilege at the resource level.

Memory trick: Resource Policies: 'R'estrict 'P'ermissions on the 'R'esource itself.

More Security questions