Courseiva

DVA-C02 Development with AWS Services Practice Question

Which TWO actions should a developer take to improve the security of an AWS Lambda function that processes sensitive data?

⚠ Common exam trap

Watch out — candidates often think a DLQ (Option A) improves security by handling failures, but it is a reliability mechanism, not a security control, and they may overlook that running a Lambda in a VPC (Option D) is a security measure to isolate network traffic, even though it is not directly about encrypting data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Encrypt environment variables using AWS KMS

Encrypting environment variables with AWS KMS ensures that sensitive data, such as database credentials or API keys, is protected at rest and in transit during function deployment. This is a critical security best practice because environment variables are visible in plaintext in the Lambda console and API responses unless encrypted. KMS provides envelope encryption, where a customer master key (CMK) encrypts the data key that encrypts the environment variables, giving you full control over access and key rotation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use a dead-letter queue (DLQ) for failed invocations

    Why it's wrong here

    DLQs are primarily designed for asynchronous error handling, ensuring that messages which fail processing are not lost and can be inspected or reprocessed later. While crucial for operational reliability and message durability in event-driven architectures, a dead-letter queue does not directly enhance the *security posture* of the Lambda function itself, as it doesn't protect data at rest, control network access, or manage credentials.

  • ✓

    Encrypt environment variables using AWS KMS

    Why this is correct

    Encrypting environment variables with AWS Key Management Service (KMS) ensures that sensitive data, such as API keys or database credentials, is protected when stored at rest within the Lambda service configuration. This prevents unauthorized access to these secrets if the Lambda configuration is compromised, as the data remains encrypted until the function is invoked and decrypted by the Lambda runtime using the specified KMS key.

  • ✗

    Grant the Lambda function full access to all S3 buckets

    Why it's wrong here

    Granting a Lambda function full access to all S3 buckets severely violates the principle of least privilege, a fundamental security best practice. This overly permissive policy allows the function to perform any S3 action on any bucket, far beyond what its legitimate purpose likely requires, significantly increasing the blast radius if the function's execution role is compromised. Instead, permissions should be precisely scoped to only the necessary actions and specific resources.

  • ✓

    Run the Lambda function inside a VPC

    Why this is correct

    Running a Lambda function inside a Virtual Private Cloud (VPC) provides essential network isolation and control, allowing the function to securely access private resources within the VPC, such as RDS databases or EC2 instances, without traversing the public internet. This significantly enhances security by enabling the use of security groups and network ACLs to restrict inbound and outbound traffic, preventing unauthorized network access to or from the function.

  • ✗

    Store secrets in the Lambda function code

    Why it's wrong here

    Storing secrets directly within the Lambda function code is a severe security vulnerability that should always be avoided. These hardcoded credentials can be easily exposed through source code repositories, deployment packages, or even during debugging, making them accessible to unauthorized individuals. Best practices dictate using secure secret management services like AWS Secrets Manager or AWS Systems Manager Parameter Store to retrieve secrets at runtime.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.