Certified Cloud Security Professional (CCSP)Cloud Security OperationsHard

A cloud security architect is designing a continuous security monitoring solution for a serverless application that utilizes API Gateway, Lambda functions, and DynamoDB. Traditional agent-based monitoring is not feasible. Which combination of cloud-native services would provide the most comprehensive security visibility for this serverless architecture?

  1. AVirtual Machine (VM) agents, network intrusion detection systems (NIDS), and host-based firewalls.
  2. BWeb Application Firewall (WAF) for API Gateway, database activity monitoring (DAM) for DynamoDB, and manual Lambda function auditing.
  3. CCloud-native logging, API activity monitoring, and serverless application tracing.
  4. DTraditional SIEM deployed on IaaS, complemented by periodic manual code reviews.
Show answer & explanation

Correct answer: C. Cloud-native logging, API activity monitoring, and serverless application tracing.

For serverless architectures, cloud-native logging (e.g., CloudWatch Logs, Stackdriver Logging) provides event data, API activity monitoring (e.g., CloudTrail, Cloud Audit Logs) tracks control plane actions, and serverless application tracing (e.g., AWS X-Ray, Azure Application Insights) offers visibility into function execution and inter-service calls. This combination provides comprehensive visibility beyond traditional host-based methods.

Why the other options are wrong

  • A. VM agents, NIDS, and host-based firewalls are irrelevant for serverless architectures as there are no underlying VMs or traditional networks to monitor.
  • B. While WAF and DAM are good, 'manual Lambda auditing' isn't continuous, and this option misses the crucial logging and tracing of the entire serverless workflow.
  • D. Deploying a traditional SIEM on IaaS without proper serverless connectors is insufficient, and manual code reviews are not continuous monitoring.

Serverless Security Monitoring

The practice of continuously collecting and analyzing security-relevant data from serverless components (e.g., functions, APIs, databases) using cloud-native tools.

  • Differs from traditional monitoring due to ephemeral nature and lack of OS access.
  • Relies on cloud-native logging, API monitoring, and distributed tracing.
  • Focuses on events, configurations, and inter-service communication.

Memory trick: For serverless, 'Logs, APIs, and Trace' are your eyes and ears.

More Cloud Security Operations questions