Skip to content
CAS-005
Security Architecture
hard
Question 4 of 27

During an architecture review of a serverless application, a security architect discovers that multiple Lambda functions share a single overprivileged IAM execution role with full S3 and DynamoDB access. Applying zero trust principles, what is the MOST appropriate remediation?

AEnable CloudTrail logging on all Lambda invocations
BAssign each Lambda function a dedicated IAM execution role scoped to only the specific resources and actions it requires
CAdd a web application firewall in front of the API Gateway
DEnable VPC endpoint policies to restrict S3 access

Educational Content — CertQnA practice questions are written against official exam objectives, covering the same domains tested on the real exam. All content is original and independent — not actual exam questions, not affiliated with any certification vendor. Learn more about our content policy

Discussion

Be the first to share your understanding of this concept

⚠️ Discussion is for concept clarification only. Do not share or request actual exam questions or answers.

Sign in to join the discussion