AWS Certified DevOps Engineer – ProfessionalConfiguration Management and Infrastructure as CodeMedium

A software development company is adopting a microservices architecture on AWS. Each microservice is deployed as an AWS Lambda function. These Lambda functions need to interact with various AWS services, such as Amazon S3, DynamoDB, and other Lambda functions. To ensure least privilege and maintain a clear separation of concerns, the security team requires that each Lambda function has a specific, minimal set of permissions defined directly within its serverless application model (SAM) template. Which SAM template property should be used to define these fine-grained permissions for a Lambda function?

  1. AAWS::Serverless::Function.ManagedPolicyArns
  2. BAWS::Serverless::Function.Policies
  3. CAWS::Serverless::Function.Role
  4. DAWS::Serverless::Function.PermissionsBoundary
Show answer & explanation

Correct answer: B. AWS::Serverless::Function.Policies

The `Policies` property within `AWS::Serverless::Function` allows you to define inline IAM policies directly in the SAM template, granting specific, fine-grained permissions to the Lambda function's execution role. This directly addresses the requirement for least privilege and clear separation of concerns by embedding the permissions within the function's definition.

Why the other options are wrong

  • A. `ManagedPolicyArns` attaches existing AWS managed policies, which might be too broad for least privilege.
  • C. `Role` specifies an existing IAM role ARN or allows SAM to create a default role, but `Policies` defines the inline permissions.
  • D. `PermissionsBoundary` sets a maximum permissions boundary, but doesn't grant actual permissions.

SAM Function Policies

In AWS Serverless Application Model (SAM), the `Policies` property for an `AWS::Serverless::Function` resource allows you to define specific IAM permissions directly within the function's template. These policies are attached to the Lambda function's execution role, enabling fine-grained control over what the function can access.

  • Grants least privilege directly to the function's execution role.
  • Supports inline policies defined in the SAM template.
  • Can use predefined SAM policy templates or custom IAM policy statements.
  • Essential for security and separation of concerns in microservices.

Memory trick: For precise Lambda permissions, use `Policies` directly in SAM.

More Configuration Management and Infrastructure as Code questions