AWS Certified Developer – Associate (DVA-C02)SecurityHard

A developer needs to create an AWS Lambda function that retrieves secrets from AWS Secrets Manager. The Lambda function will be invoked by an API Gateway endpoint. What is the MINIMUM set of permissions required for the Lambda execution role to allow it to retrieve a specific secret named 'MyDatabaseSecret' from Secrets Manager?

  1. Asecretsmanager:GetSecretValue
  2. Bsecretsmanager:GetSecretValue and secretsmanager:DescribeSecret
  3. Csecretsmanager:GetSecretValue, secretsmanager:DescribeSecret, and kms:Decrypt
  4. Dsecretsmanager:GetSecretValue and kms:Decrypt
Show answer & explanation

Correct answer: D. secretsmanager:GetSecretValue and kms:Decrypt

To retrieve a secret, the Lambda function's execution role needs 'secretsmanager:GetSecretValue'. Additionally, since Secrets Manager encrypts secrets using AWS KMS, the role also needs 'kms:Decrypt' permission for the KMS key used to encrypt the secret. 'DescribeSecret' is not strictly necessary for just retrieving the value.

Why the other options are wrong

  • A. This is insufficient; KMS decryption permission is also required for encrypted secrets.
  • B. This is insufficient; KMS decryption permission is also required. DescribeSecret is not strictly needed for retrieval.
  • C. This includes an unnecessary permission ('secretsmanager:DescribeSecret') for the sole purpose of retrieving the secret value.

Secrets Manager Retrieval Permissions

To retrieve a secret from AWS Secrets Manager, the principal (e.g., Lambda role) requires 'secretsmanager:GetSecretValue' and 'kms:Decrypt' permissions on the respective resources.

  • GetSecretValue is for accessing the secret content.
  • Kms:Decrypt is required because Secrets Manager encrypts secrets with KMS.
  • Permissions should be scoped to the specific secret and KMS key.

Memory trick: GetSecretValue and KMS Decrypt unlock the secret.

More Security questions