AWS Certified Security – SpecialtyDomain 4: Identity and Access ManagementMedium

A company is developing a new serverless application that uses AWS Lambda functions to process data stored in Amazon S3. The Lambda functions need to read from a source S3 bucket and write to a destination S3 bucket. The security team insists on implementing the principle of least privilege. Which is the MOST secure way to grant the Lambda functions access to the S3 buckets?

  1. AUse an S3 VPC endpoint policy to restrict S3 access to specific Lambda functions.
  2. BGrant the Lambda execution role `s3:FullAccess` and attach a bucket policy to each S3 bucket to restrict access.
  3. CAttach an IAM policy to the Lambda execution role that grants `s3:GetObject` for the source bucket and `s3:PutObject` for the destination bucket.
  4. DGrant `s3:*` permissions to the Lambda execution role and rely solely on S3 ACLs for access control.
Show answer & explanation

Correct answer: C. Attach an IAM policy to the Lambda execution role that grants `s3:GetObject` for the source bucket and `s3:PutObject` for the destination bucket.

Attaching an IAM policy directly to the Lambda execution role with only the necessary `s3:GetObject` for the source and `s3:PutObject` for the destination bucket adheres strictly to the principle of least privilege, granting only the required actions to the Lambda function.

Why the other options are wrong

  • A. S3 VPC endpoint policies control network access to S3 from a VPC, but do not define the specific IAM permissions for a Lambda function.
  • B. `s3:FullAccess` violates the principle of least privilege, even with bucket policies, as it grants unnecessary permissions.
  • D. `s3:*` grants overly broad permissions, violating the principle of least privilege. S3 ACLs are an older access control mechanism and less flexible than IAM policies and bucket policies.

Principle of Least Privilege

Granting only the permissions required to perform a specific task, and nothing more.

  • Reduces the attack surface by limiting potential damage from compromised credentials.
  • Should be applied to all IAM users, roles, and resources.
  • Requires careful analysis of necessary actions for each component.

Memory trick: Imagine a key that only opens one specific door, not a master key for the whole building.

More Domain 4: Identity and Access Management questions