AWS Certified Solutions Architect – Associate (SAA-C03)Design Secure ArchitecturesMedium

A media company is building a serverless application using AWS Lambda functions and Amazon DynamoDB. The Lambda functions need to read and write data to DynamoDB, and also upload processed files to an Amazon S3 bucket. The security team requires that the Lambda functions only have the absolute minimum permissions necessary for their operations. Which approach should be used to grant these permissions?

  1. AAttach an IAM policy that grants s3:* and dynamodb:* permissions to the Lambda execution role.
  2. BAttach an IAM policy that grants s3:PutObject, s3:GetObject, dynamodb:GetItem, and dynamodb:PutItem to the Lambda execution role.
  3. CAttach an IAM policy with AdministratorAccess to the Lambda execution role.
  4. DAttach an IAM policy that grants s3:*, dynamodb:*, and lambda:* permissions to the Lambda execution role.
Show answer & explanation

Correct answer: B. Attach an IAM policy that grants s3:PutObject, s3:GetObject, dynamodb:GetItem, and dynamodb:PutItem to the Lambda execution role.

The principle of least privilege dictates that an entity should only be granted the minimum permissions required to perform its task. The Lambda function needs to read/write DynamoDB (GetItem, PutItem) and upload/download S3 files (PutObject, GetObject). Option C provides exactly these permissions, adhering to the principle of least privilege.

Why the other options are wrong

  • A. s3:* and dynamodb:* grant all actions on S3 and DynamoDB respectively, which is excessive and violates the principle of least privilege.
  • C. AdministratorAccess grants full control over the AWS account, which is a severe violation of the principle of least privilege.
  • D. s3:* and dynamodb:* are too broad, and lambda:* is unnecessary for a Lambda execution role unless the function needs to manage other Lambda functions, which is not stated in the scenario.

IAM Least Privilege

The security principle of granting only the minimum permissions required for a user or service to perform its intended functions.

  • Reduces the attack surface by limiting potential damage from compromised credentials.
  • Requires careful analysis of required actions for each role/user.
  • Achieved by specifying precise actions and resources in IAM policies.

Memory trick: Just Enough Access: No More, No Less.

More Design Secure Architectures questions