AWS Certified Solutions Architect – Associate (SAA-C03)Design Secure ArchitecturesMedium
A media company is building a serverless application using AWS Lambda functions and Amazon S3. The Lambda functions need to access specific objects in an S3 bucket. The company wants to implement the principle of least privilege. How should the Solutions Architect grant the Lambda function access to the S3 bucket?
- AAttach an S3 bucket policy that grants `s3:*` permissions to all Lambda functions in the account.
- BGrant the Lambda function's IAM role administrative privileges to the entire AWS account.
- CCreate an IAM role for the Lambda function and attach an inline policy granting `s3:GetObject` on the specific S3 bucket and object prefix.
- DAttach an IAM policy to the Lambda function's execution role that grants `s3:GetObject` and `s3:PutObject` on all S3 buckets.
Show answer & explanationAnswer & explanation
Correct answer: C. Create an IAM role for the Lambda function and attach an inline policy granting `s3:GetObject` on the specific S3 bucket and object prefix.
Creating an IAM role specifically for the Lambda function and attaching a policy that grants only the necessary `s3:GetObject` permission (or other specific actions) on the required S3 bucket and object prefix adheres to the principle of least privilege, ensuring the function has only the permissions it needs.
Why the other options are wrong
- A. Granting `s3:*` to all Lambda functions is overly permissive and violates the principle of least privilege, allowing unrestricted access to all S3 resources.
- B. Granting administrative privileges to any application component, especially a Lambda function, is a severe security breach and completely violates the principle of least privilege.
- D. Granting `s3:GetObject` and `s3:PutObject` on all S3 buckets is too broad and violates the principle of least privilege, potentially allowing unintended access or modifications.
IAM Least Privilege
Granting only the permissions required to perform a specific task, and no more.
- Crucial for security in AWS.
- Achieved through granular IAM policies.
- Limits the blast radius in case of compromise.
Memory trick: Lambda's Role: Only What It Needs to Get.