A global financial institution is undergoing a major digital transformation, migrating legacy applications to a serverless architecture on a public cloud. The cybersecurity architect must implement a security operations strategy that provides robust, real-time threat detection and response for these ephemeral serverless functions and their underlying cloud infrastructure, without relying on traditional agent-based solutions. Which approach is MOST effective for this highly dynamic environment?
- AFocusing on static application security testing (SAST) during the development phase.
- BImplementing host-based intrusion detection systems (HIDS) on the underlying compute instances.
- CDeploying a traditional Security Information and Event Management (SIEM) system to collect cloud logs.
- DUtilizing cloud-native security services (e.g., AWS GuardDuty, Azure Security Center) and integrating them with a serverless-aware Cloud Workload Protection Platform (CWPP).
Show answer & explanationAnswer & explanation
Correct answer: D. Utilizing cloud-native security services (e.g., AWS GuardDuty, Azure Security Center) and integrating them with a serverless-aware Cloud Workload Protection Platform (CWPP).
For serverless architectures, agent-based solutions are not feasible. The most effective strategy involves utilizing cloud-native security services (which provide platform-level threat detection for serverless and infrastructure) combined with a serverless-aware Cloud Workload Protection Platform (CWPP). This CWPP extends protection to the function code itself, offering runtime protection, vulnerability scanning, and compliance for ephemeral workloads without agents.
Why the other options are wrong
- A. SAST is crucial for finding vulnerabilities in code pre-deployment, but it does not provide real-time threat detection or runtime protection against attacks targeting deployed serverless functions or the cloud control plane.
- B. HIDS relies on agents installed on hosts, which is not applicable to serverless functions where the underlying infrastructure is managed by the cloud provider and not directly accessible for agent deployment.
- C. While SIEM collects logs, it often lacks the real-time, granular context and automated response capabilities specifically needed for fast-changing serverless environments and may struggle with the volume/variety of cloud-native logs without significant customization.
Serverless CWPP + Cloud-Native Security
This strategy combines cloud provider's built-in security services with a specialized Cloud Workload Protection Platform (CWPP) tailored for serverless, providing comprehensive, agentless runtime protection and threat detection.
- Leverages cloud provider's inherent security capabilities.
- CWPP provides runtime protection for ephemeral serverless functions.
- Offers agentless security for highly dynamic environments.
Memory trick: Serverless needs native eyes and a function shield, no agents allowed.