CCSP Cloud Platform and Infrastructure Security Practice Question
A cloud security engineer is responsible for securing a serverless application built on AWS Lambda. The application processes sensitive customer data and writes results to an Amazon S3 bucket. The engineer must ensure that the Lambda function has only the permissions it needs to write to that specific bucket, and that the credentials are not hardcoded. Which approach should the engineer take?
⚠ Common exam trap
The trap here is thinking that storing keys in Secrets Manager is secure enough, but it still uses long-term credentials instead of temporary role-based access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an IAM role with a policy granting s3:PutObject to the specific bucket and attach it to the Lambda function.
The best practice for granting permissions to AWS Lambda is to use an IAM role with a narrowly scoped policy. The role provides temporary credentials that are automatically rotated, and the policy grants only the required s3:PutObject permission to the specific bucket. This adheres to least privilege and eliminates the need for hardcoded or stored long-term credentials. Other options involve long-term credentials or insecure storage, which are not recommended.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use an IAM user with an inline policy for S3 access and configure the Lambda function to use those credentials via the AWS SDK.
Why it's wrong here
Using an IAM user with long-term credentials for a Lambda function is not recommended. It requires managing and rotating keys manually and can lead to over-privileged access. IAM roles provide temporary credentials and are the preferred method for granting permissions to AWS services like Lambda.
- ✗
Embed the access keys in the Lambda function's environment variables.
Why it's wrong here
Embedding access keys in environment variables is insecure because they can be exposed in logs or to anyone with access to the function configuration. It also requires manual rotation and does not follow least privilege. This method is strongly discouraged by AWS security best practices.
- ✓
Create an IAM role with a policy granting s3:PutObject to the specific bucket and attach it to the Lambda function.
Why this is correct
This approach follows the principle of least privilege by granting only the necessary permission to the specific bucket. The IAM role is assumed by the Lambda function at runtime, and AWS automatically rotates the temporary credentials. This eliminates hardcoded credentials and ensures secure access. It is the recommended best practice for Lambda functions.
- ✗
Store IAM user access keys in AWS Secrets Manager and retrieve them in the Lambda function code.
Why it's wrong here
While Secrets Manager securely stores secrets, using long-term IAM user access keys is not best practice. It increases risk because the keys are static and must be rotated manually. Lambda functions should use IAM roles for temporary credentials. This approach also violates least privilege if the user has broader permissions than needed.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.