**Why Lambda security**: Lambda executes your code; compromised function = access to everything the role allows. **IAM**: Assign minimal role—only permissions needed. Avoid wildcards; scope resources (e.g., specific bucket/prefix). Use resource-based policies for cross-account....
This easy-level Cloud/Tools question appears frequently in data engineering interviews at companies like Daniel Wellington. While less common, it tests deeper understanding that distinguishes strong candidates.
Start by clearly defining the core concept being asked about. Interviewers want to see that you understand the fundamentals before diving into implementation details. Structure your answer with a definition, then explain the practical application with a concise example.
Why Lambda security: Lambda executes your code; compromised function = access to everything the role allows. IAM: Assign minimal role—only permissions needed. Avoid wildcards; scope resources (e.g., specific bucket/prefix). Use resource-based policies for cross-account. VPC: Place in private subnets when accessing RDS, ElastiCache, or internal APIs. Use VPC endpoints for S3/DynamoDB to avoid NAT and public internet. VPC adds cold-start latency—only use when necessary. Additional: Encrypt env vars with KMS; never put secrets in plaintext. Set reserved concurrency to prevent runaway cost. Use DLQ for failed async invocations. Enable X-Ray and CloudWatch Logs. Code signing for deployment integrity. Scalability: VPC Lambda needs ENI—high concurrency requires sufficient IPs in subnet. Cost: Reserved concurrency guarantees capacity but can increase cost if underutilized.
Want feedback on your answer?
Paste your answer to this question and our AI Coach scores it, finds gaps, and shows you the FAANG-level version.
Get the most asked SQL questions with expert answers. Instant download.
No spam. Unsubscribe anytime.
Paste your answer and get instant AI feedback with a FAANG-level improved version.
Analyze My Answer — FreeAccording to DataEngPrep.tech, this is one of the most frequently asked Cloud/Tools interview questions, reported at 1 company. DataEngPrep.tech maintains a curated database of 1,863+ real data engineering interview questions across 7 categories, verified by industry professionals.