Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cloud SecurityMedium

A development team is implementing a serverless application using AWS Lambda. They want to ensure that the Lambda functions can only access the specific AWS S3 buckets required for their operation and nothing else. Which AWS security best practice should they implement to achieve this granular access control?

  1. AImplement client-side encryption for all data stored in the S3 buckets.
  2. BApply a strict Network Access Control List (NACL) to the VPC containing the Lambda function.
  3. CAttach an IAM policy with the principle of least privilege to the Lambda execution role.
  4. DConfigure an AWS WAF to block unauthorized S3 access attempts.
Show answer & explanation

Correct answer: C. Attach an IAM policy with the principle of least privilege to the Lambda execution role.

IAM policies are the primary mechanism for controlling access to AWS resources. By attaching a finely-tuned IAM policy to the Lambda function's execution role, the principle of least privilege can be enforced, granting access only to the specific S3 buckets and actions required.

Why the other options are wrong

  • A. Client-side encryption protects data at rest but does not control which identities can access the buckets.
  • B. NACLs control network traffic at the subnet level, not granular access to specific S3 buckets.
  • D. WAFs protect web applications from exploits, not direct programmatic access to S3 from a Lambda function.

AWS IAM Least Privilege

The security principle of granting users, roles, or services only the minimum permissions necessary to perform their intended tasks in AWS. This minimizes the potential blast radius of a security incident.

  • Achieved through carefully crafted IAM policies.
  • Reduces risk by limiting unauthorized access.
  • Essential for secure cloud operations, especially with serverless functions.

Memory trick: IAM is the 'I'dentity 'A'nd 'M'aster key for AWS resources.

More Cloud Security questions