Cisco CCNP Security Core (SCOR) 350-701Cloud SecurityHard

An organization is adopting a serverless architecture for its new application, utilizing AWS Lambda, API Gateway, and DynamoDB. The security team is concerned about potential vulnerabilities introduced through the custom code deployed in Lambda functions, as well as maintaining proper access controls between the serverless components. Which security best practice is crucial for minimizing the attack surface and ensuring secure communication and execution within this serverless environment?

  1. AImplementing a traditional network firewall with stateful inspection.
  2. BApplying the Principle of Least Privilege to IAM roles for Lambda functions and other services.
  3. CUsing a dedicated Virtual Private Cloud (VPC) for each Lambda function.
  4. DDeploying a hardware security module (HSM) for each DynamoDB table.
Show answer & explanation

Correct answer: B. Applying the Principle of Least Privilege to IAM roles for Lambda functions and other services.

In serverless architectures, traditional network firewalls are less relevant. Instead, granular access control through IAM roles, strictly adhering to the Principle of Least Privilege, is critical. This ensures Lambda functions only have permissions to access necessary resources (like specific DynamoDB tables) and API Gateway can only invoke authorized functions, significantly reducing the attack surface.

Why the other options are wrong

  • A. Traditional network firewalls are less effective or applicable in a serverless environment where network abstraction is high, and functions are ephemeral.
  • C. While Lambda can run within a VPC, using a dedicated VPC for *each* function is overly complex, costly, and not the primary method for securing communication *between* serverless components or minimizing the attack surface from code vulnerabilities.
  • D. HSMs are used for key management and hardware-level encryption, which is important for data protection, but not the primary best practice for minimizing the attack surface and securing communication/execution *between* serverless components themselves.

Serverless Security Best Practices

Security considerations and techniques specifically applied to serverless architectures to mitigate unique risks.

  • Focus on IAM roles and Least Privilege.
  • Validate and sanitize all input.
  • Secure API Gateway endpoints.
  • Monitor function execution and logs.

Memory trick: Serverless: Less servers, more focus on identity and input.

More Cloud Security questions