AWS Certified Developer – Associate (DVA-C02)SecurityMedium

A developer is creating a new serverless application using AWS Lambda and Amazon API Gateway. The Lambda function needs to retrieve a secret (e.g., a database password) from AWS Secrets Manager. The security team insists on the principle of least privilege. What is the MINIMUM IAM permission required for the Lambda function's execution role to retrieve a specific secret named `prod/my_app/db_password` from Secrets Manager?

  1. A`secretsmanager:*` on `*`
  2. B`secretsmanager:GetSecretValue` on `arn:aws:secretsmanager:REGION:ACCOUNT_ID:secret:*`
  3. C`secretsmanager:GetSecretValue` on `arn:aws:secretsmanager:REGION:ACCOUNT_ID:secret:prod/my_app/db_password`
  4. D`secretsmanager:DescribeSecret` on `arn:aws:secretsmanager:REGION:ACCOUNT_ID:secret:prod/my_app/db_password`
Show answer & explanation

Correct answer: C. `secretsmanager:GetSecretValue` on `arn:aws:secretsmanager:REGION:ACCOUNT_ID:secret:prod/my_app/db_password`

To adhere to the principle of least privilege, the Lambda function should only be granted permission to perform the `GetSecretValue` action on the specific ARN of the secret it needs to retrieve. Option B precisely defines this minimum required permission.

Why the other options are wrong

  • A. This grants full access to Secrets Manager on all resources, a major security risk and a violation of least privilege.
  • B. This grants access to *all* secrets (`:*`) in the account, violating the principle of least privilege for a specific secret.
  • D. `DescribeSecret` allows viewing metadata about the secret, but not retrieving its actual value. `GetSecretValue` is needed.

Secrets Manager Retrieval Permissions

To retrieve a secret from AWS Secrets Manager, an IAM principal (e.g., Lambda execution role) requires the `secretsmanager:GetSecretValue` permission. This permission should be scoped to the specific secret's ARN to follow the principle of least privilege.

  • Action: `secretsmanager:GetSecretValue`.
  • Resource: Specific secret ARN for least privilege.
  • IAM policy attached to the requesting entity (e.g., Lambda role, EC2 instance profile).

Memory trick: Specific Secret, Specific Action: No more, no less.

More Security questions