AWS Certified Developer – Associate (DVA-C02)SecurityMedium

A developer is building a serverless application using AWS Lambda and Amazon API Gateway. The Lambda functions need to interact with an Amazon RDS PostgreSQL database instance. The database credentials (username and password) must be rotated regularly and never hardcoded in the Lambda function code. Which approach provides the MOST secure and automated way to manage and access these database credentials?

  1. AUse AWS Secrets Manager to store and rotate credentials, integrating with the Lambda function.
  2. BStore credentials in environment variables for the Lambda function and manually rotate them.
  3. CEncrypt credentials using AWS KMS and store them in an S3 bucket, decrypting them at runtime.
  4. DStore credentials in AWS Systems Manager Parameter Store and retrieve them at runtime.
Show answer & explanation

Correct answer: A. Use AWS Secrets Manager to store and rotate credentials, integrating with the Lambda function.

AWS Secrets Manager is specifically designed for storing, managing, and automatically rotating secrets like database credentials. It integrates with various AWS services, including RDS, to automate rotation and provides secure access for Lambda functions, preventing hardcoding.

Why the other options are wrong

  • B. Environment variables are not suitable for sensitive data like credentials, especially with rotation requirements, and manual rotation is not automated.
  • C. While S3 with KMS can store encrypted data, it requires custom logic for rotation and is not as integrated or automated for database credentials as Secrets Manager.
  • D. Parameter Store can store secrets, but Secrets Manager offers automated rotation and more robust features specifically designed for database credentials.

AWS Secrets Manager for DB Credentials

AWS Secrets Manager helps you protect secrets needed to access your applications, services, and IT resources. The service enables you to easily rotate, manage, and retrieve database credentials, API keys, and other secrets throughout their lifecycle.

  • Automated secret rotation for RDS, Redshift, DocumentDB.
  • Integration with Lambda for secure retrieval.
  • Fine-grained access control using IAM.

Memory trick: Secrets Manager Rotates Credentials Safely.

More Security questions