Courseiva
Security →hardMultiple Select

DVA-C02 Security Practice Question

Which TWO security best practices should be applied when using AWS Lambda? (Choose TWO.)

⚠ Common exam trap

Candidates often confuse operational best practices (like enabling CloudWatch Logs) with security best practices, or they mistakenly believe that environment variables are a safe place to store secrets because they are not visible in the function code itself. However, environment variables are visible to anyone with access to view the Lambda configuration, making AWS Secrets Manager the secure choice.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Attach an IAM execution role with least privilege permissions.

Option A is correct because every Lambda function assumes an IAM execution role to call other AWS services, and granting only the specific actions and resources the function needs (least privilege) limits the blast radius if the function is compromised or misused. Option E is correct because AWS Secrets Manager stores credentials and other secrets encrypted and lets the function retrieve them at runtime via the AWS SDK, so secrets are not embedded in code or configuration and can be rotated automatically. Option B is not a security best practice in this context; CloudWatch Logs is primarily for observability and monitoring, and logging sensitive data can even increase exposure. Option C is wrong because hardcoding database credentials in function code exposes secrets in source control, deployment packages, and logs. Option D is wrong because Lambda environment variables are not a secure secret store—they are visible in the function configuration and can be exposed through console access, APIs, or misconfigured permissions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Attach an IAM execution role with least privilege permissions.

    Why this is correct

    An IAM execution role defines the permissions that the Lambda function assumes when it executes. Applying the principle of least privilege means granting only the specific permissions required for the function to perform its intended tasks, such as reading from an S3 bucket or writing to a DynamoDB table, and nothing more. This significantly reduces the potential blast radius if the function is compromised, as an attacker would only gain access to the limited set of authorized actions.

  • ✗

    Enable CloudWatch Logs for the Lambda function.

    Why it's wrong here

    While enabling CloudWatch Logs is crucial for monitoring, debugging, and auditing Lambda function invocations and performance, it is not inherently a security best practice in the sense of preventing unauthorized access or data breaches. CloudWatch Logs provides visibility into what the function is doing, which can aid in security investigations post-incident, but it doesn't directly implement security controls or reduce the attack surface of the function itself.

  • ✗

    Hardcode database credentials in the function code.

    Why it's wrong here

    Hardcoding sensitive information like database credentials directly within the Lambda function's code is a severe security vulnerability. This practice exposes the credentials to anyone with access to the source code repository or the deployed function package, making them easily discoverable and exploitable. It violates the principle of separation of concerns and makes credential rotation extremely difficult and error-prone, significantly increasing the risk of unauthorized database access.

  • ✗

    Store sensitive data in Lambda environment variables.

    Why it's wrong here

    Storing sensitive data, such as API keys or database connection strings, directly in Lambda environment variables is not a secure practice. While AWS encrypts these variables at rest, they are decrypted and readily visible in plain text within the AWS Management Console and via API calls (e.g., GetFunctionConfiguration) to anyone with appropriate IAM permissions to view the function's configuration. This exposure makes them vulnerable to insider threats or compromised AWS credentials, failing to protect secrets effectively.

  • ✓

    Use AWS Secrets Manager to retrieve secrets at runtime.

    Why this is correct

    AWS Secrets Manager is a dedicated service designed for securely storing, managing, and retrieving sensitive credentials, such as database passwords, API keys, and other secrets. By integrating Secrets Manager, the Lambda function can fetch the latest version of a secret at runtime, ensuring that credentials are never hardcoded or stored insecurely within the function or its environment variables. Secrets Manager also facilitates automatic rotation of secrets, further enhancing security posture and reducing operational overhead.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

This DVA-C02 question is part of Courseiva's 1,135-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.