A cloud security architect is designing a continuous security monitoring solution for a serverless application that utilizes API Gateway, Lambda functions, and DynamoDB. Traditional agent-based monitoring is not feasible. Which combination of cloud-native services would provide the most comprehensive security visibility for this serverless architecture?
- AVirtual Machine (VM) agents, network intrusion detection systems (NIDS), and host-based firewalls.
- BWeb Application Firewall (WAF) for API Gateway, database activity monitoring (DAM) for DynamoDB, and manual Lambda function auditing.
- CCloud-native logging, API activity monitoring, and serverless application tracing.
- DTraditional SIEM deployed on IaaS, complemented by periodic manual code reviews.
Show answer & explanationAnswer & explanation
Correct answer: C. Cloud-native logging, API activity monitoring, and serverless application tracing.
For serverless architectures, cloud-native logging (e.g., CloudWatch Logs, Stackdriver Logging) provides event data, API activity monitoring (e.g., CloudTrail, Cloud Audit Logs) tracks control plane actions, and serverless application tracing (e.g., AWS X-Ray, Azure Application Insights) offers visibility into function execution and inter-service calls. This combination provides comprehensive visibility beyond traditional host-based methods.
Why the other options are wrong
- A. VM agents, NIDS, and host-based firewalls are irrelevant for serverless architectures as there are no underlying VMs or traditional networks to monitor.
- B. While WAF and DAM are good, 'manual Lambda auditing' isn't continuous, and this option misses the crucial logging and tracing of the entire serverless workflow.
- D. Deploying a traditional SIEM on IaaS without proper serverless connectors is insufficient, and manual code reviews are not continuous monitoring.
Serverless Security Monitoring
The practice of continuously collecting and analyzing security-relevant data from serverless components (e.g., functions, APIs, databases) using cloud-native tools.
- Differs from traditional monitoring due to ephemeral nature and lack of OS access.
- Relies on cloud-native logging, API monitoring, and distributed tracing.
- Focuses on events, configurations, and inter-service communication.
Memory trick: For serverless, 'Logs, APIs, and Trace' are your eyes and ears.