Certified Cloud Security Professional (CCSP)Cloud Security OperationsMedium

A cloud security architect is tasked with implementing continuous security monitoring for a serverless application that processes sensitive financial transactions. Due to the ephemeral nature and rapid scaling of serverless functions, traditional agent-based monitoring is impractical. Which approach is best suited for real-time security visibility in this serverless environment?

  1. APerforming weekly penetration tests against the application endpoints
  2. BDeploying host-based intrusion detection systems (HIDS) on each function instance
  3. CAnalyzing cloud provider-generated logs (e.g., CloudWatch Logs, Azure Monitor) and function-level metrics
  4. DImplementing a web application firewall (WAF) in front of the serverless functions
Show answer & explanation

Correct answer: C. Analyzing cloud provider-generated logs (e.g., CloudWatch Logs, Azure Monitor) and function-level metrics

For serverless environments, traditional agent-based monitoring is not feasible due to the ephemeral and managed nature of the underlying infrastructure. The most effective approach for real-time security visibility relies on collecting and analyzing the comprehensive logs and metrics natively provided by the cloud provider for serverless functions, such as execution logs, invocation metrics, and API gateway logs.

Why the other options are wrong

  • A. Penetration tests are periodic assessments, not a continuous, real-time monitoring solution.
  • B. HIDS are agent-based and cannot be deployed on ephemeral, managed serverless function instances.
  • D. A WAF protects the edge of the application and can filter malicious requests, but it does not provide internal real-time security visibility into the execution and behavior of individual serverless functions.

Serverless Security Monitoring

Focuses on leveraging cloud provider-native logging, metrics, and API integrations due to the ephemeral and managed nature of serverless functions.

  • Traditional agents are impractical.
  • Relies heavily on cloud provider logs and metrics.
  • Integrates with SIEM/observability platforms.

Memory trick: Look to the cloud's own logs for serverless secrets.

More Cloud Security Operations questions