AWS Certified Developer – Associate (DVA-C02)Development with AWS ServicesHard
A developer is writing an AWS Lambda function that needs to access resources in a private Amazon VPC, such as an Amazon RDS database. The Lambda function is currently configured to run outside of a VPC. What is the MINIMUM change required to allow the Lambda function to securely access the RDS database?
- AGrant the Lambda execution role direct internet access to the RDS database endpoint.
- BConfigure a VPC endpoint for AWS Lambda in the VPC.
- CCreate a NAT Gateway in the VPC and route all Lambda traffic through it.
- DConfigure the Lambda function to run inside the VPC by specifying VPC subnets and security groups.
Show answer & explanationAnswer & explanation
Correct answer: D. Configure the Lambda function to run inside the VPC by specifying VPC subnets and security groups.
To access resources within a private VPC, a Lambda function must be configured to execute within that VPC. This involves specifying subnets and security groups, which allows the Lambda function to obtain a network interface in the VPC and communicate with other private resources.
Why the other options are wrong
- A. RDS databases in private subnets are not accessible directly from the internet for security reasons. Granting internet access to the Lambda role would not enable access to a private RDS instance.
- B. VPC endpoints for Lambda allow resources *within* a VPC to invoke Lambda functions or for Lambda functions *within* a VPC to access other AWS services *privately*. It doesn't enable a Lambda function *outside* a VPC to access resources *inside* it.
- C. A NAT Gateway is used to allow instances *within* a private subnet to access the internet, not to allow Lambda functions *outside* the VPC to access resources *inside* it. If a Lambda *in* a private subnet needs internet, it would use NAT Gateway, but the primary issue is getting Lambda *into* the VPC.
Lambda in a VPC
Configuring an AWS Lambda function to connect to resources within a private Amazon Virtual Private Cloud (VPC), such as databases, caches, or internal services.
- Requires specifying VPC subnets and security groups.
- Lambda creates an Elastic Network Interface (ENI) in the VPC.
- Allows secure access to private resources.
- Requires appropriate security group rules and routing.
Memory trick: Lambda needs a VPC passport to enter the private network.