Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cloud SecurityMedium
A cloud security team is evaluating the use of serverless functions (Function-as-a-Service) for event-driven applications. They need to ensure that each function has only the minimum necessary permissions to perform its specific task, adhering to the principle of least privilege. What is the most effective way to implement this security control for serverless functions?
- ARelying on network security groups to control access for serverless functions.
- BAssigning broad administrative roles to all serverless functions for flexibility.
- CCreating granular IAM policies specific to each function's required resources and actions.
- DUsing a single, highly privileged role for all functions within an application.
Show answer & explanationAnswer & explanation
Correct answer: C. Creating granular IAM policies specific to each function's required resources and actions.
Creating granular IAM policies specific to each function's required resources and actions is the most effective way to implement the principle of least privilege for serverless functions. This ensures that each function only has the permissions it absolutely needs, minimizing its attack surface.
Why the other options are wrong
- A. Network security groups control network access, but do not manage the specific resource-level permissions (e.g., S3 bucket access, database writes) that IAM policies handle for serverless functions.
- B. Assigning broad administrative roles violates the principle of least privilege and creates significant security risks.
- D. Using a single, highly privileged role for multiple functions also violates least privilege, as functions may get unnecessary permissions.
Serverless Least Privilege
Applying the principle of least privilege to serverless functions by granting only the essential permissions required for each function to perform its specific task.
- Minimizes potential damage from compromised functions
- Reduces the attack surface
- Requires careful design of IAM policies
Memory trick: Give each serverless function its own tiny, specific key.