Grant the report Lambda Security Hub read-only access because findings are already in Security Hub
A company wants to automate the creation of a security report. The company has an AWS Lambda function that gathers data from Amazon Inspector findings stored in AWS Security Hub in the us-west-2 Region. The Lambda function then needs to create a daily report by using an Amazon EventBridge schedule. A security engineer discovers that the Lambda function is failing to create the report. The security engineer must implement a solution that corrects the issue and provides least privilege permissions. Which solution will meet these requirements?
Community Votes
50% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The Lambda consumes findings from Security Hub, not by calling Inspector APIs, so Inspector permissions are unnecessary. The least-privilege fix is Security Hub read-only access (AWSSecurityHubReadOnlyAccess). Granting Inspector read as well (option C) or a broad custom Batch* policy (option D) exceeds what the function needs.
A Lambda builds a daily report from Amazon Inspector findings that are stored in AWS Security Hub. Because the data already resides in Security Hub, the function only needs permission to read Security Hub findings—not Amazon Inspector directly. Attaching the AWS managed AWSSecurityHubReadOnlyAccess policy to the execution role gives exactly the read access required with least privilege, fixing the failure without over-granting.
Granting both Inspector and Security Hub read access (option C) on the assumption the function needs Inspector—it reads findings from Security Hub, so Inspector access is surplus. Or a custom policy with Batch* actions (option D), which is broader than read-only and riskier.
Community Discussion (10 comments)
- enabling more than read access...
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.