AWS Certified Developer – Associate (DVA-C02)DeploymentHard

A security-conscious development team needs to deploy an AWS Lambda function that processes sensitive customer data. The function must only be invoked by a specific Amazon SQS queue in the same AWS account and region, and no other service or user should be able to trigger it. How should the developer configure the Lambda function's permissions to meet this requirement?

  1. AConfigure a resource-based policy directly on the Lambda function, granting 'lambda:InvokeFunction' permission to the SQS queue's ARN as the principal.
  2. BSet up an AWS WAF rule to block any invocation requests to the Lambda function that do not originate from the SQS service endpoint.
  3. CAttach an IAM policy to the Lambda execution role that explicitly denies invocation from all sources except the SQS queue ARN.
  4. DModify the SQS queue's access policy to allow it to invoke the specific Lambda function, and leave the Lambda permissions default.
Show answer & explanation

Correct answer: A. Configure a resource-based policy directly on the Lambda function, granting 'lambda:InvokeFunction' permission to the SQS queue's ARN as the principal.

Resource-based policies directly attached to the Lambda function are the correct and most granular way to control invocation permissions. By specifying the SQS queue's ARN as the principal, you ensure only that specific queue can invoke the function, adhering to the principle of least privilege.

Why the other options are wrong

  • B. AWS WAF is designed for web application firewalls and does not control service-to-service invocation permissions for Lambda.
  • C. Denying all and then allowing specific can be complex and prone to errors. Resource-based policies are more direct for invocation.
  • D. SQS queue policies control who can send messages to the queue, not who the queue can invoke. Lambda's permissions must be configured to allow SQS to invoke it.

Lambda Resource-Based Policy

A policy attached directly to an AWS Lambda function, granting specific AWS services or accounts permission to invoke the function or perform other actions on it.

  • Controls who can invoke the Lambda function.
  • Uses the invoking service's ARN as the principal.
  • Essential for secure service-to-service communication with Lambda.

Memory trick: Lambda's door (resource policy) only opens for specific keys (principals).

More Deployment questions