Certified Cloud Security Professional (CCSP)Cloud Concepts, Architecture and DesignMedium

A cloud security engineer is tasked with securing a serverless application that processes sensitive financial transactions. The application consists of multiple Lambda functions. Which security challenge is most critical to address for this serverless architecture?

  1. AManaging virtual machine network configurations.
  2. BMaintaining underlying operating system patches.
  3. CSecuring API gateways and function permissions.
  4. DMonitoring physical server hardware health.
Show answer & explanation

Correct answer: C. Securing API gateways and function permissions.

In serverless architectures, the cloud provider manages the underlying infrastructure (OS, VMs, hardware). The customer's primary security responsibility shifts to securing the application code, API gateways (entry points), and defining appropriate permissions for functions.

Why the other options are wrong

  • A. VM network configurations are abstracted away and managed by the provider in serverless.
  • B. OS patching is typically managed by the cloud provider in a serverless model.
  • D. Physical server monitoring is entirely the cloud provider's responsibility.

Serverless Security Challenges

Security considerations specific to serverless computing, where the cloud provider manages servers and infrastructure, shifting customer focus to application-level security.

  • Focus on function code security, API gateway protection, and IAM.
  • Reduced visibility into underlying infrastructure.
  • Increased attack surface through numerous, often small, functions and event triggers.

Memory trick: Serverless security: The provider handles the 'house', you secure the 'doors' (APIs) and 'contents' (functions).

More Cloud Concepts, Architecture and Design questions