Courseiva
Security →mediumMultiple Select

DVA-C02 Security Practice Question

A developer is using AWS Lambda and needs to ensure that the function can access an RDS database securely. Which THREE steps should be taken?

⚠ Common exam trap

DVA-C02 often tests the misconception that IAM permissions alone are sufficient for Lambda-to-RDS access, ignoring the need for VPC networking and security group rules.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Place the Lambda function inside a VPC.

Option A is correct because a Lambda function can only reach an RDS instance that resides in a VPC if the function itself is configured with VPC connectivity (subnets and a security group), which is required for private network access to the database. Option B is correct because hardcoding credentials is insecure; storing them in AWS Secrets Manager and retrieving them at runtime (optionally with Lambda's Secrets Manager extension/caching) keeps the database password encrypted and rotatable. Option E is correct because RDS access is controlled by security group rules, so the RDS instance's security group must allow inbound traffic on the database port (e.g., 3306 for MySQL, 5432 for PostgreSQL) referencing the Lambda function's security group as the source. Option C is not appropriate because rds:* IAM permissions govern the RDS control plane API, not the ability to open a database connection, and Lambda's execution role does not grant network access to RDS. Option D is not required for this scenario; client certificate authentication is an optional RDS TLS feature and is not one of the standard steps to let Lambda connect securely.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Place the Lambda function inside a VPC.

    Why this is correct

    By default, Lambda functions run in an AWS-owned VPC and cannot connect to resources in your private subnets. Attaching the function to the same VPC provisions elastic network interfaces in your subnets, giving it private IP connectivity to the RDS instance. This is the foundational step required before any TCP connection to RDS can be established.

  • ✓

    Store the database credentials in AWS Secrets Manager and retrieve them in the Lambda code.

    Why this is correct

    Hardcoding database passwords in Lambda environment variables or code creates a security risk and makes rotation difficult. Secrets Manager lets the function call GetSecretValue at runtime to retrieve the current credentials, with IAM permissions controlling which functions may access the secret. This addresses authentication, not networking, so it complements the VPC setup but does not replace it.

  • ✗

    Attach an IAM role to the Lambda function that grants rds:* permissions.

    Why it's wrong here

    An IAM role defines permissions for AWS API actions, not for database logins. rds:* would let the Lambda call RDS management endpoints like CreateDBInstance or DescribeDBInstances, but RDS still expects a database user name and password in the connection string. Even when using IAM database authentication, the correct permission is rds-db:connect for a specific database resource, not the blanket rds:* policy, so this option cannot authenticate the function.

  • ✗

    Configure the RDS instance to require client certificates.

    Why it's wrong here

    Client certificate verification is a mutual TLS feature that proves the identity of the connecting application, but Lambda functions do not natively present a client certificate for RDS connections. Standard drivers for MySQL, Postgres, or SQL Server do not automatically use the certificate associated with an IAM role or execution environment. Even if enabled, this does not resolve network access or provide the database password, so it is irrelevant to the core requirement and would likely break the connection.

  • ✓

    Configure the security group of the RDS instance to allow inbound traffic from the Lambda function's security group.

    Why this is correct

    After the Lambda is placed in the VPC, its associated security group becomes the source for outbound connections, so the RDS instance's security group must permit inbound traffic on the database port from that security group. This stateful rule limits the database to only accept traffic from the Lambda's network interface, providing a precise control plane. It is necessary to actually open the path, but it only works if the Lambda has already been attached to the VPC.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

Courseiva writes every DVA-C02 question from scratch — 1,135 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.