Courseiva

CCSP Cloud Platform and Infrastructure Security Practice Question

During a security review of a serverless application, you notice that a Lambda function's execution role has permissions to delete all S3 buckets in the account. What is the most appropriate remediation to align with the principle of least privilege?

⚠ Common exam trap

CCSP often tests least privilege by offering plausible-sounding but non-authorization fixes (environment variables, VPC changes) — candidates must recognize that only IAM policy scoping actually reduces permissions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a custom IAM role that grants only the necessary actions on a specific S3 bucket

The correct remediation is to replace the overly permissive execution role with a custom IAM role scoped to only the specific S3 actions and the specific bucket the Lambda function actually needs. This directly enforces least privilege by eliminating the wildcard delete permissions across all buckets. AWS IAM evaluates the policy attached to the Lambda execution role on every API call, so narrowing the Resource ARN and Action list constrains the blast radius if the function is compromised.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create a custom IAM role that grants only the necessary actions on a specific S3 bucket

    Why this is correct

    A custom IAM role scoped to only the necessary actions on a specific S3 bucket removes the wildcard delete permissions, directly enforcing least privilege for the Lambda execution role instead of leaving account-wide destructive access.

  • ✗

    Store S3 bucket names in environment variables instead of hardcoding

    Why it's wrong here

    Environment variables only change where bucket names are stored, not the role's IAM permissions, so the delete-all-buckets capability remains. This is tempting as a secrets-management or configuration hardening measure, and would be correct when the concern is credential exposure rather than excessive permissions.

  • ✗

    Attach the AWS managed policy 'AmazonS3ReadOnlyAccess'

    Why it's wrong here

    AmazonS3ReadOnlyAccess grants read access to every bucket in the account, still broader than the function needs and not scoped to specific resources. It is tempting because it removes the delete capability, and would be correct if the function genuinely required read access across all buckets.

  • ✗

    Remove the Lambda function's VPC integration

    Why it's wrong here

    VPC integration controls network routing and reachability, not IAM authorisation, so the execution role still permits deleting every S3 bucket. It is tempting because network isolation is a recognised serverless hardening step, and would be correct when the requirement is to restrict outbound traffic or reach private resources.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.