Certified Cloud Security Professional (CCSP)Cloud Platform and Infrastructure SecurityMedium
A financial institution is migrating its legacy applications to a serverless architecture in the cloud. The security team is particularly concerned about the potential for code injection vulnerabilities and excessive permissions granted to the serverless functions. Which of the following strategies BEST mitigates these two specific risks?
- AScanning serverless function code for vulnerabilities and enforcing least privilege with IAM policies.
- BEncrypting all data processed by serverless functions and implementing robust logging.
- CUtilizing container isolation for each serverless function and network segmentation.
- DImplementing API Gateway for all function invocations and using a WAF.
Show answer & explanationAnswer & explanation
Correct answer: A. Scanning serverless function code for vulnerabilities and enforcing least privilege with IAM policies.
Scanning serverless function code for vulnerabilities directly addresses code injection risks by identifying flaws before deployment. Enforcing least privilege with IAM policies directly mitigates the risk of excessive permissions by ensuring functions only have the minimum necessary access to perform their intended tasks.
Why the other options are wrong
- B. Encryption protects data confidentiality and logging aids in forensics, but neither directly prevents code injection vulnerabilities or limits excessive function permissions.
- C. Container isolation is not typically applicable to pure serverless functions (which are event-driven and managed by the CSP's runtime) and network segmentation is a broader control that doesn't specifically target code injection or excessive permissions.
- D. API Gateway and WAF protect the function's ingress point from external attacks but do not directly address vulnerabilities within the function's code or its internal permissions.
Serverless Security Controls
Specific security practices tailored to protect serverless functions and applications from common threats.
- Code scanning to prevent injection.
- Least privilege IAM for function roles.
- Input validation is crucial.
Memory trick: Scan the code and grant least privilege, for serverless safety you must give.