AWS Certified Developer – Associate (DVA-C02)SecurityMedium
A company is developing a new serverless application using AWS Lambda functions. This application needs to access a relational database hosted on Amazon RDS. The database credentials (username and password) must be stored securely and rotated automatically without requiring changes to the Lambda function code. The development team wants to retrieve these credentials at runtime. Which AWS service should they use?
- AAWS Secrets Manager
- BEnvironment variables in Lambda
- CAWS Systems Manager Parameter Store
- DAmazon S3
Show answer & explanationAnswer & explanation
Correct answer: A. AWS Secrets Manager
AWS Secrets Manager is specifically designed for securely storing, retrieving, and rotating database credentials and other secrets automatically. It integrates with RDS for automated rotation without code changes.
Why the other options are wrong
- B. Storing sensitive credentials directly in Lambda environment variables is insecure and does not provide automatic rotation.
- C. Systems Manager Parameter Store can store secrets, but it does not natively support automatic rotation of database credentials for RDS without additional custom Lambda functions.
- D. Storing credentials in Amazon S3, even in encrypted buckets, is not considered a best practice for dynamic credential management and lacks automatic rotation capabilities.
Secrets Manager for DB Credentials
AWS Secrets Manager securely stores and automatically rotates database credentials (e.g., for RDS) and other secrets. Applications retrieve these secrets at runtime, avoiding hardcoding.
- Secure storage of credentials.
- Automatic rotation for RDS.
- Retrieve secrets at runtime.
- Avoids hardcoding sensitive data.
Memory trick: Secrets Manager rotates DB keys, keeping Lambda code clean.