AWS Certified Developer – Associate (DVA-C02)DeploymentHard

A developer needs to ensure that an AWS Lambda function, which processes sensitive customer data, can only be invoked by an Amazon API Gateway endpoint and no other AWS service or user. Which security mechanism should be implemented on the Lambda function?

  1. AEncrypt the Lambda function code with KMS.
  2. BUse a VPC endpoint for API Gateway.
  3. CApply a resource-based policy to the Lambda function.
  4. DConfigure an IAM role for API Gateway with invoke permissions.
Show answer & explanation

Correct answer: C. Apply a resource-based policy to the Lambda function.

A resource-based policy (also known as a Lambda policy) attached directly to the Lambda function allows you to specify which AWS services or accounts can invoke that function, including granular conditions like the source ARN of the API Gateway. This directly addresses the requirement for restricting invocation to a specific API Gateway.

Why the other options are wrong

  • A. Encrypting the Lambda function code with KMS protects the code at rest but does not control invocation permissions.
  • B. A VPC endpoint for API Gateway secures network access to the API Gateway but does not control who can invoke the Lambda function from the API Gateway.
  • D. An IAM role for API Gateway grants API Gateway permissions to *access other AWS services*, not to restrict *who can invoke* the Lambda function itself.

Lambda Resource-Based Policy

A resource-based policy (or Lambda policy) is an IAM policy attached directly to an AWS Lambda function. It specifies which principals (AWS accounts, services, or users) can invoke the function and what actions they can perform, often used to grant invocation permissions from services like API Gateway or S3.

  • Attached directly to the Lambda function.
  • Grants invocation permissions to specific principals.
  • Can include conditions (e.g., source ARN).
  • Crucial for controlling cross-service access.

Memory trick: Lambda's policy: the bouncer at the function's door, API Gateway's the only one allowed anymore.

More Deployment questions