AWS Certified Developer – Associate (DVA-C02)Development with AWS ServicesMedium

A developer is building an application that needs to retrieve sensitive configuration parameters, such as API keys and database connection strings, from AWS Systems Manager Parameter Store. The Lambda function retrieving these parameters is configured with an IAM role. For maximum security, how should the developer retrieve these parameters, ensuring they are decrypted automatically if encrypted?

  1. AUse `ssm.get_parameter(Name='param_name', WithDecryption=True)`.
  2. BAccess parameters directly from Lambda environment variables configured with encrypted values.
  3. CUse `ssm.get_parameters(Names=['param_name'], WithDecryption=True)`.
  4. DUse `ssm.get_parameter(Name='param_name', WithDecryption=False)` and decrypt manually.
Show answer & explanation

Correct answer: A. Use `ssm.get_parameter(Name='param_name', WithDecryption=True)`.

To retrieve encrypted parameters from AWS Systems Manager Parameter Store and have them automatically decrypted, the `WithDecryption` parameter must be set to `True` in the `get_parameter` API call. The Lambda's IAM role must have permissions for `ssm:GetParameter` and `kms:Decrypt`.

Why the other options are wrong

  • B. While Lambda environment variables can be encrypted, Parameter Store offers more robust management, versioning, and integration with KMS for sensitive configuration, making `get_parameter` a better choice for this scenario.
  • C. `get_parameters` is for retrieving multiple parameters; while `WithDecryption=True` is correct, `get_parameter` is sufficient for a single parameter and typically preferred if only one is needed.
  • D. `WithDecryption=False` would return the encrypted value, requiring manual decryption, which is less secure and more complex.

SSM get_parameter (WithDecryption)

The `get_parameter` API call with `WithDecryption=True` in AWS Systems Manager Parameter Store automatically decrypts encrypted parameters using AWS KMS.

  • Requires the calling IAM role to have `kms:Decrypt` permissions.
  • Simplifies retrieval of sensitive, encrypted configuration data.
  • Parameter Store handles the KMS interaction transparently.

Memory trick: To 'get' a 'parameter' that's a 'secret', remember to ask for 'Decryption' to complete the feat.

More Development with AWS Services questions