hardMultiple Choice
CAS-004 Practice Question: Is analyzing a serverless application that uses…
A security engineer is analyzing a serverless application that uses AWS Lambda. Which of the following is the most critical security concern when the function processes external input?
⚠ Common exam trap
CAS-005 often tests the misconception that serverless functions are inherently secure because they are managed, leading candidates to overlook injection risks and pick configuration-related options.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The function may be vulnerable to injection attacks if input is not sanitized
Injection attacks (e.g., SQL injection, command injection) are the most critical security concern for serverless functions processing external input because Lambda functions often interact with databases or execute commands. If input is not sanitized, attackers can execute arbitrary code or access data. This is a top OWASP risk and directly applies to any application handling untrusted input.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The function may be vulnerable to injection attacks if input is not sanitized
Why this is correct
Lambda functions that process external input pass untrusted data into downstream queries or commands, so unsanitised input enables injection attacks; this is the most critical concern because it can compromise data and execution context directly.
- ✗
The function has a timeout of 5 minutes
Why it's wrong here
A five-minute timeout is a resilience and cost consideration, not an input-handling control; it neither validates nor sanitises untrusted data. It is tempting because timeouts limit runaway execution and denial-of-service exposure, so they would be the right focus when tuning availability or billing rather than addressing injection or deserialisation flaws in external input.
- ✗
The function uses environment variables for configuration
Why it's wrong here
Environment variables store configuration, so they do not themselves process or validate untrusted input; the risk is only indirect if secrets are exposed in logs or the console. They are tempting because they are the standard way to inject runtime settings into Lambda, and would be the correct concern when auditing credential storage rather than input handling.
- ✗
The function does not use a custom runtime
Why it's wrong here
A custom runtime affects language support and packaging, not how external input is parsed or validated; the managed runtimes receive security patches from AWS. It is tempting because custom runtimes shift patching responsibility to the team, so they would be the correct focus when the requirement is controlling the execution environment rather than defending against malicious payloads.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.