AWS Certified DevOps Engineer – ProfessionalConfiguration Management and Infrastructure as CodeMedium
A company is implementing a new application using AWS Lambda functions. These Lambda functions need to access specific S3 buckets and DynamoDB tables. The security team insists on granting only the minimum necessary permissions to each Lambda function. The DevOps team wants to automate the creation and management of these permissions as part of their Infrastructure as Code (IaC) pipeline using AWS SAM (Serverless Application Model). Which SAM resource type should they use to define these fine-grained permissions for their Lambda functions?
- AAWS::IAM::Policy
- BAWS::Serverless::Application `Permissions` property
- CAWS::Serverless::Function `Policies` property
- DAWS::IAM::Role
Show answer & explanationAnswer & explanation
Correct answer: C. AWS::Serverless::Function `Policies` property
In AWS SAM, the `Policies` property within an `AWS::Serverless::Function` resource allows you to define inline IAM policies or reference managed policies, directly granting fine-grained permissions to the Lambda function's execution role. This is the most idiomatic way to manage Lambda permissions within SAM templates.
Why the other options are wrong
- A. While `AWS::IAM::Policy` can define policies, SAM provides a more integrated and concise way to attach them directly to functions via the `Policies` property.
- B. There is no `Permissions` property for `AWS::Serverless::Application`; permissions are typically defined at the `AWS::Serverless::Function` level or via explicit IAM resources.
- D. An `AWS::IAM::Role` resource defines the role itself, but SAM's `Policies` property is for defining the *permissions attached to that role* for the function.
SAM Function Policies
The `Policies` property of an `AWS::Serverless::Function` resource in AWS SAM templates, used to define the IAM permissions granted to the Lambda function's execution role.
- Simplifies IAM policy definition for Lambda functions.
- Supports both inline policies and managed policy references.
- Enforces least privilege directly within the function definition.
Memory trick: SAM function, its policies defined, least privilege for its kind.