Certified Cloud Security Professional (CCSP)Cloud Application SecurityEasy
A cloud application uses serverless functions (e.g., AWS Lambda, Azure Functions) to process user requests. Each function has specific permissions defined by an associated IAM role. To adhere to the principle of least privilege, how should these permissions be configured for optimal security?
- ADefining granular permissions that allow each function to access only the specific resources and actions required for its task.
- BGranting each function full administrative access to all cloud resources it might interact with.
- CAssigning a single, broad IAM role to all serverless functions within the application.
- DRelying on network security groups to restrict outbound access from the serverless functions.
Show answer & explanationAnswer & explanation
Correct answer: A. Defining granular permissions that allow each function to access only the specific resources and actions required for its task.
The principle of least privilege dictates that each entity (in this case, a serverless function) should only be granted the minimum permissions necessary to perform its intended task, which is achieved through granular IAM role definitions.
Why the other options are wrong
- B. Granting full administrative access violates the principle of least privilege and creates a significant security risk.
- C. Assigning a broad IAM role to all functions also violates least privilege, as some functions will have unnecessary access.
- D. Network security groups control network access but do not manage permissions for cloud resources, which is the role of IAM.
Principle of Least Privilege (PoLP)
A security principle requiring that a user or process be given only the minimum necessary authorization to perform its function.
- Reduces the attack surface.
- Limits the impact of a compromise.
- Applies to users, applications, and services.
Memory trick: Least Privilege: 'Just Enough, Not Too Much' access.