Certified Cloud Security Professional (CCSP)Cloud Platform and Infrastructure SecurityEasy

A global enterprise is migrating its legacy applications to a serverless architecture to reduce operational overhead and improve scalability. The security team is concerned about potential over-permissioning of serverless functions, which could lead to privilege escalation if a function is compromised. Which principle should be strictly applied when defining IAM roles for these serverless functions?

  1. ADefense in Depth
  2. BLeast Privilege
  3. CSeparation of Duties
  4. DShared Responsibility
Show answer & explanation

Correct answer: B. Least Privilege

Applying the principle of Least Privilege ensures that each serverless function is granted only the minimum permissions necessary to perform its intended task, significantly reducing the impact of a compromise.

Why the other options are wrong

  • A. Defense in Depth involves multiple layers of security controls, a general strategy, not specific to function permissions.
  • C. Separation of Duties prevents a single individual from controlling an entire process, which is broader than function permissions.
  • D. Shared Responsibility defines who is responsible for what in the cloud, not how permissions are set for functions.

Least Privilege (Serverless)

The security principle of granting a serverless function only the minimum necessary permissions to perform its specific task, reducing the attack surface and potential impact of compromise.

  • Crucial for mitigating privilege escalation risks.
  • Requires careful analysis of each function's needs.
  • Often implemented using fine-grained IAM policies.

Memory trick: For serverless functions, give them the LEAST amount of keys they need to do their job, no more. Don't hand them the master key to the whole house!

More Cloud Platform and Infrastructure Security questions