AWS Certified Security – SpecialtyDomain 3: Infrastructure SecurityEasy

A company is deploying a new serverless application using AWS Lambda functions. The Lambda functions need to access resources within a private VPC, including an Amazon RDS database and an Amazon ElastiCache cluster. The security team insists that the Lambda functions must not have any public internet access. Which configuration is necessary to meet these requirements?

  1. AConfigure the Lambda functions to run within a public subnet in the VPC and attach a Security Group.
  2. BConfigure the Lambda functions with a VPC endpoint for RDS and ElastiCache.
  3. CConfigure the Lambda functions to run within private subnets in the VPC, and attach appropriate Security Groups.
  4. DConfigure the Lambda functions to run within private subnets in the VPC, and provide a NAT Gateway for internet access.
Show answer & explanation

Correct answer: C. Configure the Lambda functions to run within private subnets in the VPC, and attach appropriate Security Groups.

Configuring Lambda functions to run within private subnets in a VPC allows them to securely access resources like RDS and ElastiCache (which are typically in private subnets) without exposing the Lambda functions to the public internet. Attaching appropriate Security Groups controls ingress/egress for the Lambda ENIs.

Why the other options are wrong

  • A. Running Lambda in a public subnet would make it publicly accessible, violating the 'no public internet access' requirement.
  • B. VPC endpoints are for private access to AWS services outside the VPC (e.g., S3, DynamoDB). RDS and ElastiCache are typically deployed *within* the VPC, so Lambda functions in the same VPC can access them directly via private IP addresses without VPC endpoints.
  • D. While NAT Gateway provides internet access for private subnets, the requirement states 'must not have any public internet access'. Adding a NAT Gateway would grant outbound internet access, which contradicts the requirement.

Lambda VPC Configuration

Connecting AWS Lambda functions to a Virtual Private Cloud (VPC) by configuring them to run within private subnets, allowing secure access to private VPC resources.

  • Lambda ENIs are created in specified subnets.
  • Private subnets restrict public internet access.
  • Security Groups control traffic to/from Lambda ENIs.
  • No NAT Gateway if no internet access is required.

Memory trick: Lambda's VPC Home: Private Subnets, Secure Talk!

More Domain 3: Infrastructure Security questions