AWS Certified Security – SpecialtyDomain 3: Infrastructure SecurityMedium

A software development company is building a new serverless application using AWS Lambda functions. The Lambda functions need to access sensitive data stored in an Amazon RDS PostgreSQL database, which is located in a private subnet. The company requires that all connections from the Lambda functions to the database are private and do not traverse the public internet. How should the Lambda functions be configured to meet this requirement securely?

  1. AConfigure the Lambda functions to run within the same VPC as the RDS database, in a private subnet, and ensure the RDS security group allows inbound traffic from the Lambda's security group.
  2. BKeep the Lambda functions outside the VPC and configure a VPC Endpoint for RDS to allow private access.
  3. CConfigure the Lambda functions to run within the same VPC as the RDS database, in a private subnet, and use a NAT Gateway for outbound internet access.
  4. DConfigure the Lambda functions to run within the same VPC as the RDS database, in a public subnet, and ensure the RDS security group allows inbound traffic from the Lambda's public IP.
Show answer & explanation

Correct answer: A. Configure the Lambda functions to run within the same VPC as the RDS database, in a private subnet, and ensure the RDS security group allows inbound traffic from the Lambda's security group.

Placing Lambda functions in a private subnet within the same VPC as the RDS database ensures that traffic between them remains private. Using security groups to control access by referencing the Lambda's security group provides granular and dynamic access control without exposing anything to the public internet.

Why the other options are wrong

  • B. VPC Endpoints are for accessing AWS services (like S3, DynamoDB) privately from within a VPC, not for connecting Lambda to a private RDS instance within the same VPC.
  • C. While placing Lambda in a private subnet is correct, using a NAT Gateway is for outbound internet access, not for private communication with RDS within the same VPC.
  • D. Placing Lambda in a public subnet and allowing inbound traffic from its public IP to RDS exposes the database connection to potential public internet exposure, violating the 'private' requirement.

Lambda VPC Integration

To securely access resources in a private VPC subnet (like RDS) from AWS Lambda, the Lambda function must be configured to run within that VPC and use private networking.

  • Lambda in VPC allows access to private resources.
  • Place Lambda in private subnets for security.
  • Use security groups for granular access control.
  • Traffic remains within the AWS network, not public internet.

Memory trick: Lambda Lives in VPC, Links to RDS Privately.

More Domain 3: Infrastructure Security questions