AWS Certified Developer – Associate (DVA-C02)Development with AWS ServicesEasy
A developer is implementing an AWS Lambda function that processes images uploaded to an Amazon S3 bucket. The function needs to resize the images and store the resized versions in another S3 bucket. The developer wants to ensure that the Lambda function only has the necessary permissions to read from the source S3 bucket and write to the destination S3 bucket. Which IAM policy principle should be applied?
- APrinciple of Fault Tolerance
- BPrinciple of Least Privilege
- CPrinciple of Shared Responsibility
- DPrinciple of Separation of Duties
Show answer & explanationAnswer & explanation
Correct answer: B. Principle of Least Privilege
The Principle of Least Privilege dictates that an entity (like a Lambda function) should only be granted the minimum permissions necessary to perform its intended function. In this case, read from the source bucket and write to the destination bucket.
Why the other options are wrong
- A. Fault Tolerance relates to designing systems that can withstand failures, not about access control or permissions.
- C. The Shared Responsibility Model defines security responsibilities between AWS and the customer, not how to grant permissions to a single resource.
- D. Separation of Duties involves distributing tasks among multiple individuals to prevent conflicts of interest or fraud, not directly about resource permissions.
Principle of Least Privilege
A security best practice that states that any user, program, or process should be given only the minimum privileges necessary to perform its task.
- Reduces the attack surface.
- Limits the impact of security breaches.
- Essential for secure application development in AWS.
Memory trick: Least Privilege: Only the keys you need for the doors you open.