AWS Certified Security – SpecialtyDomain 4: Identity and Access ManagementEasy
A development team uses AWS CodeBuild to run CI/CD pipelines. The CodeBuild projects need to retrieve source code from a private Amazon S3 bucket, publish build artifacts to another S3 bucket, and update an Amazon DynamoDB table with build status. The security team wants to apply the principle of least privilege. Which approach ensures CodeBuild projects have only the necessary permissions?
- AAttach an IAM policy to the CodeBuild service role that grants read/write access to all S3 buckets and DynamoDB tables in the account.
- BGrant the CodeBuild service role AdministratorAccess and rely on project-level IAM policies to restrict access.
- CUse AWS KMS keys to encrypt the S3 buckets and DynamoDB table, then grant the CodeBuild role KMS decryption permissions.
- DCreate a new IAM role for each CodeBuild project with specific permissions for its S3 buckets and DynamoDB table.
Show answer & explanationAnswer & explanation
Correct answer: D. Create a new IAM role for each CodeBuild project with specific permissions for its S3 buckets and DynamoDB table.
Creating a dedicated IAM role for each CodeBuild project with only the specific permissions it needs for its S3 buckets and DynamoDB table adheres to the principle of least privilege. This ensures that a compromise of one project does not grant broad access to other resources.
Why the other options are wrong
- A. Granting broad access to all S3 buckets and DynamoDB tables in the account violates the principle of least privilege, allowing projects to access resources they don't need.
- B. Granting AdministratorAccess violates the principle of least privilege and is highly insecure, even with project-level policies which may be bypassed or misconfigured.
- C. While KMS encryption is good for data at rest, it doesn't directly address the permissions for CodeBuild to *access* those resources. The CodeBuild role still needs specific S3 and DynamoDB permissions, in addition to KMS decrypt if the data is encrypted.
Principle of Least Privilege
Security principle stating that users, programs, or processes should be given only the minimum privileges necessary to perform their work.
- Reduces the attack surface.
- Limits the blast radius of a breach.
- A fundamental security best practice.
Memory trick: CodeBuild needs specific roles, not broad access, for secure builds.