Courseiva

GSEC Virtualization, Cloud, and AI Essentials Practice Question

A media company uses a serverless function to process uploaded images. The function is triggered by object storage events and writes results to a database. A security review finds that the function's execution role grants full administrative access to all cloud services. Which action best applies the principle of least privilege to this serverless workload?

⚠ Common exam trap

The trap here is treating credential protection or network controls as equivalent to least privilege, when the finding is specifically about an execution role that grants far more permissions than the workload needs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Replace the administrative role with a role scoped to the specific object storage bucket and database table the function uses.

Least privilege for a serverless function means its execution role should grant only the actions and resources required to do its job. Replacing an administrative role with one scoped to the specific bucket and database table removes unnecessary permissions and reduces the impact of compromise. Credential encryption, concurrency limits, and network restrictions do not shrink the role's effective permissions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable function-level concurrency limits to prevent runaway executions.

    Why it's wrong here

    Concurrency limits control how many instances of the function run simultaneously, which helps with cost and availability. They do not constrain what permissions the function has. An attacker using the function's role would still have full administrative access, so this control does not address the least privilege finding.

  • ✗

    Move the function's credentials into environment variables encrypted with a customer-managed key.

    Why it's wrong here

    Encrypting credentials at rest protects them from casual disclosure, but the role still grants full administrative access once assumed. The over-privileged permissions remain the core problem, so this change does not reduce the effective privilege of the function and fails to apply least privilege.

  • ✗

    Configure the function to run inside a virtual private cloud with restrictive security groups.

    Why it's wrong here

    Network controls restrict where the function can send and receive traffic but do not limit which cloud API actions its role can perform. The function could still call administrative APIs over allowed endpoints. Since the finding is about excessive permissions rather than network reachability, this option does not remediate the issue.

  • ✓

    Replace the administrative role with a role scoped to the specific object storage bucket and database table the function uses.

    Why this is correct

    Scoping the execution role to only the bucket and table the function needs removes the broad administrative permissions and limits the blast radius if the function is compromised. This directly implements least privilege for the serverless workload while preserving its required read and write operations.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.