AWS Certified Security – SpecialtyDomain 3: Infrastructure SecurityHard

A global e-commerce company uses AWS Lambda functions to process sensitive customer order information. They need to ensure that these Lambda functions can access specific resources in a different AWS account (e.g., an S3 bucket or a DynamoDB table) securely, without sharing IAM user credentials or making the resources publicly accessible. The access must adhere to the principle of least privilege, allowing only the necessary actions. Which mechanism should be implemented to achieve this cross-account access securely?

  1. AConfigure the Lambda function's execution role with an IAM access key and secret key for the target account.
  2. BModify the resource policy (e.g., S3 bucket policy or DynamoDB table policy) in the target account to grant access to the Lambda function's execution role ARN from the source account.
  3. CCreate an IAM user in the target account, generate access keys, and store them securely in AWS Secrets Manager for the Lambda function to retrieve.
  4. DEstablish a VPC Peering connection between the VPCs where the Lambda function and the target resources reside.
Show answer & explanation

Correct answer: B. Modify the resource policy (e.g., S3 bucket policy or DynamoDB table policy) in the target account to grant access to the Lambda function's execution role ARN from the source account.

Resource-based policies (like S3 bucket policies or DynamoDB table policies) are the standard and most secure way to grant cross-account access to specific resources. By specifying the Lambda function's execution role ARN from the source account, you adhere to the principle of least privilege and avoid sharing credentials.

Why the other options are wrong

  • A. Sharing IAM access keys and secret keys is an anti-pattern and highly insecure for cross-account access.
  • C. Storing access keys in Secrets Manager is better than hardcoding, but still involves creating and managing long-lived credentials, which is less secure than using resource-based policies for cross-account access.
  • D. VPC Peering connects networks, but it does not grant access to specific AWS resources like S3 buckets or DynamoDB tables; these are accessed via API calls, not network routing.

Cross-Account Resource Access

Securely granting access to an AWS resource in one account to a principal (user, role, or service) in another account, typically using resource-based policies or IAM roles.

  • Resource-based policies (S3, SQS, KMS) are ideal for specific resources.
  • IAM roles (trust policies) allow principals to assume roles in other accounts.
  • Avoid sharing long-lived credentials.
  • Adhere to the principle of least privilege.

Memory trick: Resource Policies Reach Resources.

More Domain 3: Infrastructure Security questions