AWS Certified Developer – Associate (DVA-C02)Development with AWS ServicesHard

A developer is writing an AWS Lambda function that needs to access resources in a private Amazon VPC, such as an Amazon RDS database. The Lambda function is currently configured to run outside of a VPC. What is the MINIMUM change required to allow the Lambda function to securely access the RDS database?

  1. AGrant the Lambda execution role direct internet access to the RDS database endpoint.
  2. BConfigure a VPC endpoint for AWS Lambda in the VPC.
  3. CCreate a NAT Gateway in the VPC and route all Lambda traffic through it.
  4. DConfigure the Lambda function to run inside the VPC by specifying VPC subnets and security groups.
Show answer & explanation

Correct answer: D. Configure the Lambda function to run inside the VPC by specifying VPC subnets and security groups.

To access resources within a private VPC, a Lambda function must be configured to execute within that VPC. This involves specifying subnets and security groups, which allows the Lambda function to obtain a network interface in the VPC and communicate with other private resources.

Why the other options are wrong

  • A. RDS databases in private subnets are not accessible directly from the internet for security reasons. Granting internet access to the Lambda role would not enable access to a private RDS instance.
  • B. VPC endpoints for Lambda allow resources *within* a VPC to invoke Lambda functions or for Lambda functions *within* a VPC to access other AWS services *privately*. It doesn't enable a Lambda function *outside* a VPC to access resources *inside* it.
  • C. A NAT Gateway is used to allow instances *within* a private subnet to access the internet, not to allow Lambda functions *outside* the VPC to access resources *inside* it. If a Lambda *in* a private subnet needs internet, it would use NAT Gateway, but the primary issue is getting Lambda *into* the VPC.

Lambda in a VPC

Configuring an AWS Lambda function to connect to resources within a private Amazon Virtual Private Cloud (VPC), such as databases, caches, or internal services.

  • Requires specifying VPC subnets and security groups.
  • Lambda creates an Elastic Network Interface (ENI) in the VPC.
  • Allows secure access to private resources.
  • Requires appropriate security group rules and routing.

Memory trick: Lambda needs a VPC passport to enter the private network.

More Development with AWS Services questions