Courseiva
Infrastructure Security →mediumMultiple Choice

SCS-C02 Infrastructure Security Practice Question

A company has an AWS Lambda function that needs to access an Amazon RDS database. The database is in a private subnet. Which configuration will allow the Lambda function to securely access the database without traversing the internet?

⚠ Common exam trap

It's easy for candidates to assume Lambda functions always run inside a VPC by default, but in reality, Lambda runs in an AWS-managed VPC unless explicitly configured with VPC settings, and they mistakenly think VPC endpoints can be used for any AWS service, including RDS, when in fact RDS does not support VPC interface endpoints for database connections.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the Lambda function to run in the same VPC as the RDS database, in the same private subnet.

Placing the Lambda function in the same VPC and the same private subnet as the RDS database allows the Lambda function to communicate with the database directly over the AWS network using private IP addresses. This configuration ensures traffic does not traverse the internet, and it leverages VPC routing and security groups for access control. Lambda functions must be configured with VPC settings to access resources in private subnets, and when both are in the same subnet, no additional gateways or peering are required.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a VPC peering connection between the Lambda VPC and the RDS VPC.

    Why it's wrong here

    Lambda functions are not placed in a VPC by default; they run in an isolated environment, so there is no 'Lambda VPC' to peer. To use VPC peering, you would first need to configure the Lambda function to run in a specific VPC with subnets and security groups. Even then, peering between a Lambda's VPC and the RDS VPC is an unnecessary complication compared to simply deploying the function in the same VPC as the database. Peering is a VPC-to-VPC networking construct, not a mechanism for Lambda-to-RDS connectivity.

  • ✗

    Place the Lambda function in a public subnet and use a NAT gateway to access the RDS database.

    Why it's wrong here

    Placing the Lambda function in a public subnet does not by itself grant access to an RDS instance in a private subnet; the function must be associated with the same VPC and have proper security group rules. A NAT gateway is used for outbound internet access from private subnets, not for connecting to RDS, which is already privately reachable. If the Lambda function were in a public subnet, it would still need a route to the private RDS subnet, which is not how Lambda VPC networking works. This configuration would only be relevant if RDS needed to be reached via the internet, which is not the case here.

  • ✓

    Configure the Lambda function to run in the same VPC as the RDS database, in the same private subnet.

    Why this is correct

    Attaching the Lambda function to the VPC and placing it in the same private subnet as the RDS instance allows the function's elastic network interface to communicate directly with the database over private IP addresses. This satisfies the security group rules—Lambda can use its own security group to allow inbound traffic to RDS on the database port. There is no need for internet access or NAT, and the connection remains within the private network. This is the recommended AWS pattern for Lambda plus RDS in the same VPC.

  • ✗

    Use a VPC endpoint for Lambda to connect to the RDS database.

    Why it's wrong here

    A VPC endpoint is a PrivateLink connection that allows resources in a VPC to reach AWS services such as S3 or DynamoDB without traversing the internet. Lambda itself is not an AWS service that you connect to via a VPC endpoint for the purpose of accessing RDS; rather, the Lambda function must be deployed in the VPC to establish a network path to RDS. There is no 'Lambda VPC endpoint' that acts as a proxy for database traffic. This misconception confuses VPC endpoints for supported AWS services with the need to attach the Lambda function to the VPC.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.