DOP-C02 Configuration Management and IaC Practice Question
A DevOps engineer uses AWS Secrets Manager to rotate database credentials. The rotation fails because the Lambda function used for rotation does not have network access to the database. The database is in a private VPC. How should the engineer fix this?
⚠ Common exam trap
DOP-C02 often tests the misconception that Lambda can reach private VPC resources without being VPC-enabled, or that NAT/peering solves internal connectivity — candidates must remember Lambda needs explicit VPC attachment plus correct routing and security groups.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the Lambda function to be VPC-enabled and place it in the same subnet as the database.
The Lambda rotation function must reach the private database, so it needs to run inside the VPC with network access to the database's subnet and security group. Configuring the Lambda function to be VPC-enabled and placing it in the same subnet (or a subnet with routing to the database) allows it to resolve and connect to the private RDS/DB endpoint, fixing the rotation failure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure the Lambda function to be VPC-enabled and place it in the same subnet as the database.
Why this is correct
Correct. Enabling VPC integration for the Lambda function makes AWS attach a Hyperplane Elastic Network Interface directly inside your chosen subnets, so the function can communicate with the database over private IP addresses without crossing the internet. Placing the Lambda ENI in the same subnets (or at least with a valid local route to the DB subnet) lets traffic flow entirely within the VPC. You must still allow the Lambda ENI's security group in the database's security group inbound rule, and the subnets must have proper routing; this preserves the database's private posture, which is the key requirement for Secrets Manager rotation.
- ✗
Assign a public IP address to the database and update the security group to allow access from the Lambda function.
Why it's wrong here
Wrong. Assigning a public IP to the database exposes the database directly to the internet, dramatically expanding the attack surface and requiring extra controls like Network ACLs and monitoring; this is a security risk and violates the principle of least privilege. Worse, it doesn't guarantee Lambda can actually reach it: a VPC-enabled Lambda has no internet path unless an Internet Gateway (or NAT with public IP) is configured, and a non-VPC Lambda has ephemeral public IPs that can't be reliably whitelisted in the security group. Thus this option both weakens security and fails to create a stable, private connection path.
- ✗
Set up a VPC Peering connection between the Lambda service and the VPC.
Why it's wrong here
Wrong. VPC Peering connects two VPCs at the network layer, but the Lambda service itself is not hosted in a VPC you can peer with; Lambda execution environments run in an AWS-managed network, so there is no peering attachment to a service. You can only peer VPCs that you own (or that are shared with you), and even then the Lambda function would still need to be deployed into one of those VPCs to use the peering connection. The supported way to let Lambda reach a private database is to attach the Lambda's ENI to your VPC, not to try peering with the Lambda service.
- ✗
Add a NAT Gateway to the VPC to allow Lambda to reach the database.
Why it's wrong here
Wrong. A NAT Gateway provides outbound internet connectivity from private subnets, not inbound or east-west access between a Lambda function and a database inside the same VPC. Even if you add a NAT Gateway, a non-VPC Lambda still has no ENI in your VPC and therefore cannot use private routes or the NAT at all; a VPC-enabled Lambda already has the VPC routes necessary to reach the database directly. NAT only becomes relevant if the Lambda must reach a public endpoint while also staying in the VPC, which is the opposite of what is needed for a private database.
Visual reference
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.