DVA-C02 Development with AWS Services Practice Question
Which TWO actions should a developer take to improve the security of an AWS Lambda function that processes sensitive data?
⚠ Common exam trap
Watch out — candidates often think a DLQ (Option A) improves security by handling failures, but it is a reliability mechanism, not a security control, and they may overlook that running a Lambda in a VPC (Option D) is a security measure to isolate network traffic, even though it is not directly about encrypting data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Encrypt environment variables using AWS KMS
Encrypting environment variables with AWS KMS ensures that sensitive data, such as database credentials or API keys, is protected at rest and in transit during function deployment. This is a critical security best practice because environment variables are visible in plaintext in the Lambda console and API responses unless encrypted. KMS provides envelope encryption, where a customer master key (CMK) encrypts the data key that encrypts the environment variables, giving you full control over access and key rotation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use a dead-letter queue (DLQ) for failed invocations
Why it's wrong here
DLQs are primarily designed for asynchronous error handling, ensuring that messages which fail processing are not lost and can be inspected or reprocessed later. While crucial for operational reliability and message durability in event-driven architectures, a dead-letter queue does not directly enhance the *security posture* of the Lambda function itself, as it doesn't protect data at rest, control network access, or manage credentials.
- ✓
Encrypt environment variables using AWS KMS
Why this is correct
Encrypting environment variables with AWS Key Management Service (KMS) ensures that sensitive data, such as API keys or database credentials, is protected when stored at rest within the Lambda service configuration. This prevents unauthorized access to these secrets if the Lambda configuration is compromised, as the data remains encrypted until the function is invoked and decrypted by the Lambda runtime using the specified KMS key.
- ✗
Grant the Lambda function full access to all S3 buckets
Why it's wrong here
Granting a Lambda function full access to all S3 buckets severely violates the principle of least privilege, a fundamental security best practice. This overly permissive policy allows the function to perform any S3 action on any bucket, far beyond what its legitimate purpose likely requires, significantly increasing the blast radius if the function's execution role is compromised. Instead, permissions should be precisely scoped to only the necessary actions and specific resources.
- ✓
Run the Lambda function inside a VPC
Why this is correct
Running a Lambda function inside a Virtual Private Cloud (VPC) provides essential network isolation and control, allowing the function to securely access private resources within the VPC, such as RDS databases or EC2 instances, without traversing the public internet. This significantly enhances security by enabling the use of security groups and network ACLs to restrict inbound and outbound traffic, preventing unauthorized network access to or from the function.
- ✗
Store secrets in the Lambda function code
Why it's wrong here
Storing secrets directly within the Lambda function code is a severe security vulnerability that should always be avoided. These hardcoded credentials can be easily exposed through source code repositories, deployment packages, or even during debugging, making them accessible to unauthorized individuals. Best practices dictate using secure secret management services like AWS Secrets Manager or AWS Systems Manager Parameter Store to retrieve secrets at runtime.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.