Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cloud SecurityMedium

A cloud security team is evaluating the use of serverless functions (Function-as-a-Service) for a new microservices application. They are concerned about potential security risks associated with overly broad permissions granted to these functions. Which security best practice should they strictly adhere to when configuring IAM roles for serverless functions?

  1. ADisable logging and monitoring for serverless functions to reduce overhead.
  2. BGrant administrative privileges to all functions for ease of deployment.
  3. CUse a single, highly privileged IAM role for all serverless functions.
  4. DApply the principle of least privilege, granting only necessary permissions.
Show answer & explanation

Correct answer: D. Apply the principle of least privilege, granting only necessary permissions.

Applying the principle of least privilege is a critical security best practice for serverless functions. This means granting each function only the specific permissions required to perform its intended task, minimizing the potential blast radius if a function is compromised.

Why the other options are wrong

  • A. Disabling logging and monitoring is a poor security practice that hinders incident detection and response.
  • B. Granting administrative privileges violates least privilege and creates significant security risks.
  • C. Using a single, highly privileged role for all functions is a major security anti-pattern, violating least privilege.

Serverless Least Privilege

The security practice of granting serverless functions (e.g., AWS Lambda, Azure Functions) only the minimal set of IAM permissions required to execute their specific tasks.

  • Reduces the attack surface of serverless applications
  • Limits the scope of impact if a function is exploited
  • Requires careful analysis of function dependencies

Memory trick: Serverless Functions Need Just Enough Power.

More Cloud Security questions