A library chatbot will run as serverless functions. Which security implication should the architect highlight?
Select an answer to reveal the explanation.
Short Explanation
Serverless means you are not babysitting VMs—but you are babysitting who the function can call and which packages it pulls. Less OS patching, more IAM and dependency discipline. It is not a free pass on identity.
Full Explanation
Serverless architectures reduce customer responsibility for underlying server patching while concentrating risk in function permissions, triggers, secrets, and software dependencies. Shared runtimes and package supply chains remain relevant. Claiming serverless eliminates identity concerns, dependency risk, or forces municipal teams to manage hypervisors misstates the security tradeoffs.