AWS Certified Security – SpecialtyDomain 3: Infrastructure SecurityMedium

A company is using AWS Lambda functions to process sensitive customer data. They need to ensure that these Lambda functions can securely access an Amazon S3 bucket in a different AWS account without exposing the S3 bucket to the public internet. The security team also mandates that access should be granted with the principle of least privilege. How should this cross-account access be configured?

  1. ACreate an IAM user in the S3 account, generate access keys, and embed them in the Lambda function's environment variables.
  2. BAttach an IAM policy to the Lambda execution role that grants direct access to the S3 bucket in the other account using its ARN.
  3. CEstablish an AWS Resource Access Manager (RAM) share for the S3 bucket with the Lambda account.
  4. DConfigure a VPC endpoint for S3 in the Lambda function's VPC, and attach a bucket policy to the S3 bucket that grants access to the Lambda function's role.
Show answer & explanation

Correct answer: D. Configure a VPC endpoint for S3 in the Lambda function's VPC, and attach a bucket policy to the S3 bucket that grants access to the Lambda function's role.

A VPC endpoint for S3 allows Lambda functions within a VPC to access S3 privately, without traversing the public internet. A bucket policy on the S3 bucket, granting access to the Lambda execution role from the other account, enforces least privilege and cross-account access. This combination ensures secure and private communication.

Why the other options are wrong

  • A. Embedding access keys is an anti-pattern for security, especially for cross-account access, and does not ensure private access.
  • B. While an IAM policy on the Lambda role can grant access, it doesn't ensure private access to S3, which is a key requirement for sensitive data.
  • C. AWS RAM is used for sharing AWS resources like subnets, Resource Shares, or Transit Gateways, but not directly for granting specific cross-account access to S3 buckets for a Lambda function in this manner. S3 bucket policies are the correct mechanism.

Secure Cross-Account S3 Access for Lambda

Enabling AWS Lambda functions to securely and privately access S3 buckets in a different AWS account using VPC Endpoints and S3 Bucket Policies.

  • VPC Endpoint for S3 ensures private access.
  • S3 Bucket Policy grants cross-account access.
  • Least privilege enforced by targeting specific Lambda roles.

Memory trick: Lambda's S3 Secret: VPC Endpoint, Bucket Policy!

More Domain 3: Infrastructure Security questions