Courseiva
hardMultiple Choice

CAS-004 Practice Question: Is analyzing a serverless application that uses…

A security engineer is analyzing a serverless application that uses AWS Lambda. Which of the following is the most critical security concern when the function processes external input?

⚠ Common exam trap

CAS-005 often tests the misconception that serverless functions are inherently secure because they are managed, leading candidates to overlook injection risks and pick configuration-related options.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The function may be vulnerable to injection attacks if input is not sanitized

Injection attacks (e.g., SQL injection, command injection) are the most critical security concern for serverless functions processing external input because Lambda functions often interact with databases or execute commands. If input is not sanitized, attackers can execute arbitrary code or access data. This is a top OWASP risk and directly applies to any application handling untrusted input.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The function may be vulnerable to injection attacks if input is not sanitized

    Why this is correct

    Lambda functions that process external input pass untrusted data into downstream queries or commands, so unsanitised input enables injection attacks; this is the most critical concern because it can compromise data and execution context directly.

  • ✗

    The function has a timeout of 5 minutes

    Why it's wrong here

    A five-minute timeout is a resilience and cost consideration, not an input-handling control; it neither validates nor sanitises untrusted data. It is tempting because timeouts limit runaway execution and denial-of-service exposure, so they would be the right focus when tuning availability or billing rather than addressing injection or deserialisation flaws in external input.

  • ✗

    The function uses environment variables for configuration

    Why it's wrong here

    Environment variables store configuration, so they do not themselves process or validate untrusted input; the risk is only indirect if secrets are exposed in logs or the console. They are tempting because they are the standard way to inject runtime settings into Lambda, and would be the correct concern when auditing credential storage rather than input handling.

  • ✗

    The function does not use a custom runtime

    Why it's wrong here

    A custom runtime affects language support and packaging, not how external input is parsed or validated; the managed runtimes receive security patches from AWS. It is tempting because custom runtimes shift patching responsibility to the team, so they would be the correct focus when the requirement is controlling the execution environment rather than defending against malicious payloads.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.