EC-Council Certified Ethical Hacker (CEH) v12Cloud ComputingMedium

A security auditor is reviewing a serverless application deployed on a cloud platform. The application consists of multiple functions triggered by API Gateway events. The auditor discovers that one function has an overly permissive IAM role allowing it to read and write to all S3 buckets in the account, even though it only needs access to a single, specific bucket. This configuration introduces a significant security risk. Which principle of cloud security is being violated?

  1. ADefense in Depth
  2. BLeast Privilege
  3. CShared Responsibility Model
  4. DImmutability
Show answer & explanation

Correct answer: B. Least Privilege

The principle of Least Privilege dictates that any user, program, or process should have only the minimum necessary privileges to perform its function. The function having access to all S3 buckets when it only needs one directly violates this principle.

Why the other options are wrong

  • A. Defense in Depth involves multiple layers of security controls, which is a broader concept not specifically violated by one overly permissive role.
  • C. The Shared Responsibility Model defines who is responsible for what in cloud security, but doesn't directly address the granularity of permissions.
  • D. Immutability refers to components that do not change after deployment, which is unrelated to access permissions.

Principle of Least Privilege

A security principle requiring that a user, program, or process be given only the minimum levels of access—or permissions—necessary to perform its function.

  • Reduces the attack surface.
  • Limits the impact of a compromise.
  • Crucial for effective access control in cloud environments.

Memory trick: Least Privilege: Only unlock the doors you need to open.

More Cloud Computing questions