Cisco CCNP Security Core (SCOR) 350-701Cloud SecurityMedium
A security engineer is tasked with securing a serverless application deployed on AWS Lambda. The application processes user requests and interacts with an Amazon S3 bucket. Which security control is paramount to limit the S3 bucket's exposure only to the specific Lambda function and prevent unauthorized access?
- AApplying an S3 bucket policy with IAM conditions
- BEnabling S3 bucket versioning
- CImplementing a Web Application Firewall (WAF) in front of S3
- DConfiguring S3 Transfer Acceleration
Show answer & explanationAnswer & explanation
Correct answer: A. Applying an S3 bucket policy with IAM conditions
An S3 bucket policy, combined with IAM conditions, allows granular control over who (specifically the Lambda's IAM role) can access the bucket and what actions they can perform, thus limiting exposure precisely.
Why the other options are wrong
- B. Versioning helps recover deleted/overwritten objects but doesn't control access.
- C. WAFs protect web applications, not S3 buckets directly, and are typically deployed in front of APIs or load balancers.
- D. Transfer Acceleration speeds up uploads/downloads but has no security access control function.
AWS S3 Bucket Policy
A resource-based access policy that specifies who can access items in an S3 bucket and what actions they can perform.
- JSON-based policy attached directly to an S3 bucket.
- Can grant or deny permissions to AWS accounts, IAM users, roles, or services.
- Evaluated with IAM user policies to determine final permissions.
Memory trick: For S3, policies are the gatekeepers, IAM defines who's who.