시작하기무료로 시작하기

Give the function a narrow role

You are a backend developer on the reports team, and a teammate is about to ship a Lambda function called report-generator. It reads one object from the reports bucket each morning and writes its own log lines, and it has no identity of its own yet. Almost nothing you build runs as you personally, so before that function can call AWS it needs an execution role.

With AmazonS3ReadOnlyAccess attached, if report-generator were compromised tomorrow, what is the most it could reach?

이 연습은 강의의 일부입니다

Using AWS Security for Developers

강의 보기

실습형 인터랙티브 연습문제

이론을 실습으로 바꾸는 인터랙티브 연습 중 하나를 만나보세요

연습 시작