Grant the report Lambda Security Hub read-only access because findings are already in Security Hub

Answer Correct answer: B — attach AWSSecurityHubReadOnlyAccess; the Lambda reads findings from Security Hub, so Inspector access is unnecessary.

A company wants to automate the creation of a security report. The company has an AWS Lambda function that gathers data from Amazon Inspector findings stored in AWS Security Hub in the us-west-2 Region. The Lambda function then needs to create a daily report by using an Amazon EventBridge schedule. A security engineer discovers that the Lambda function is failing to create the report. The security engineer must implement a solution that corrects the issue and provides least privilege permissions. Which solution will meet these requirements?

  1. Create a resource-based policy that allows Security Hub access to the ARN of the Lambda function.
  2. Attach the AWSSecurityHubReadOnlyAccess AWS managed policy to the Lambda function’s execution role. Correct Answer
  3. Grant the Lambda function’s execution role read-only permissions to access Amazon Inspector and Security Hub.
  4. Create a custom IAM policy that grants the Security Hub Get, List, Batch, and Describe permissions on the arn:aws:securityhub:us-west-2::product/aws/inspector/* resource. Attach the policy to the Lambda function’s execution role.

Community Votes

B
50%
C
50%

50% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The Lambda consumes findings from Security Hub, not by calling Inspector APIs, so Inspector permissions are unnecessary. The least-privilege fix is Security Hub read-only access (AWSSecurityHubReadOnlyAccess). Granting Inspector read as well (option C) or a broad custom Batch* policy (option D) exceeds what the function needs.

A Lambda builds a daily report from Amazon Inspector findings that are stored in AWS Security Hub. Because the data already resides in Security Hub, the function only needs permission to read Security Hub findings—not Amazon Inspector directly. Attaching the AWS managed AWSSecurityHubReadOnlyAccess policy to the execution role gives exactly the read access required with least privilege, fixing the failure without over-granting.

Granting both Inspector and Security Hub read access (option C) on the assumption the function needs Inspector—it reads findings from Security Hub, so Inspector access is surplus. Or a custom policy with Batch* actions (option D), which is broader than read-only and riskier.

Community Discussion (10 comments)

TareDHakim 👍 1 Selected: B
B, there's no need for permissions to Inspector as logs already populated in Security Hub.
Asma2023 👍 2 Selected: B
beacause findings are already stored in AWS Security HUB
8acf42c 👍 3 Selected: C
By explicitly granting read-only permissions to both Amazon Inspector and Security Hub, the Lambda function will have the least privilege access it needs to retrieve findings and generate the report. This aligns with best practices.
SCSC02Q 👍 1 Selected: B
  • enabling more than read access...
SCSC02Q 👍 1 Selected: B
its B, since the Batch on D is a problem, enabling more the read access. In comparison, B provides only BatchGet so ok.
Pmktechno 👍 3 Selected: C
This approach ensures that the Lambda function has the necessary permissions to read data from Amazon Inspector and Security Hub without granting excessive permissions. It aligns with the principle of least privilege by only allowing the specific actions required for the Lambda function to perform its task.
HappyG 👍 3 Selected: C
C grants the Lambda function's execution role the necessary permissions to read from both Amazon Inspector and AWS Security Hub, but not granting excessive permissions. This approach adheres to the principle of least privilege by providing only the necessary permissions for the Lambda function to perform its task.
Palanda 👍 1 Selected: B
I agree with b
jdx000 👍 3 Selected: B
the findings are already in security hub, so only read access to security hub is needed
723993f 👍 3 Selected: D
is it not D ? or is the Batch:* a problem ? but i think there are no batch write/delete operations that can be performed on that resource arn anyways

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The Lambda gathers Inspector findings that are already aggregated in Security Hub, so it needs only Security Hub read permissions. Attaching AWSSecurityHubReadOnlyAccess to the execution role provides precisely that, adhering to least privilege and resolving the access failure without granting Inspector or write capabilities.

Why the Other Options Are Wrong

A (resource-based policy allowing Security Hub to invoke Lambda) addresses invocation, not the data-read permission the function lacks. C grants read to both Inspector and Security Hub, exceeding least privilege since the data is in Security Hub. D uses a custom policy with Batch* permissions, which is broader than read-only and less aligned with least privilege than the managed read-only policy.

Community Comment Notes

Community split B (43) vs C (43). The least-privilege argument favors B: findings are already in Security Hub, so only SH read is needed; C over-grants Inspector. A commenter noted D's Batch* is a problem and B's managed policy is read-only. B is the minimal, correct grant.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide