SCS-C02 Infrastructure Security Practice Question
A company has an AWS Lambda function that needs to access an Amazon RDS database. The database is in a private subnet. Which configuration will allow the Lambda function to securely access the database without traversing the internet?
⚠ Common exam trap
It's easy for candidates to assume Lambda functions always run inside a VPC by default, but in reality, Lambda runs in an AWS-managed VPC unless explicitly configured with VPC settings, and they mistakenly think VPC endpoints can be used for any AWS service, including RDS, when in fact RDS does not support VPC interface endpoints for database connections.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the Lambda function to run in the same VPC as the RDS database, in the same private subnet.
Placing the Lambda function in the same VPC and the same private subnet as the RDS database allows the Lambda function to communicate with the database directly over the AWS network using private IP addresses. This configuration ensures traffic does not traverse the internet, and it leverages VPC routing and security groups for access control. Lambda functions must be configured with VPC settings to access resources in private subnets, and when both are in the same subnet, no additional gateways or peering are required.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a VPC peering connection between the Lambda VPC and the RDS VPC.
Why it's wrong here
Lambda functions are not placed in a VPC by default; they run in an isolated environment, so there is no 'Lambda VPC' to peer. To use VPC peering, you would first need to configure the Lambda function to run in a specific VPC with subnets and security groups. Even then, peering between a Lambda's VPC and the RDS VPC is an unnecessary complication compared to simply deploying the function in the same VPC as the database. Peering is a VPC-to-VPC networking construct, not a mechanism for Lambda-to-RDS connectivity.
- ✗
Place the Lambda function in a public subnet and use a NAT gateway to access the RDS database.
Why it's wrong here
Placing the Lambda function in a public subnet does not by itself grant access to an RDS instance in a private subnet; the function must be associated with the same VPC and have proper security group rules. A NAT gateway is used for outbound internet access from private subnets, not for connecting to RDS, which is already privately reachable. If the Lambda function were in a public subnet, it would still need a route to the private RDS subnet, which is not how Lambda VPC networking works. This configuration would only be relevant if RDS needed to be reached via the internet, which is not the case here.
- ✓
Configure the Lambda function to run in the same VPC as the RDS database, in the same private subnet.
Why this is correct
Attaching the Lambda function to the VPC and placing it in the same private subnet as the RDS instance allows the function's elastic network interface to communicate directly with the database over private IP addresses. This satisfies the security group rules—Lambda can use its own security group to allow inbound traffic to RDS on the database port. There is no need for internet access or NAT, and the connection remains within the private network. This is the recommended AWS pattern for Lambda plus RDS in the same VPC.
- ✗
Use a VPC endpoint for Lambda to connect to the RDS database.
Why it's wrong here
A VPC endpoint is a PrivateLink connection that allows resources in a VPC to reach AWS services such as S3 or DynamoDB without traversing the internet. Lambda itself is not an AWS service that you connect to via a VPC endpoint for the purpose of accessing RDS; rather, the Lambda function must be deployed in the VPC to establish a network path to RDS. There is no 'Lambda VPC endpoint' that acts as a proxy for database traffic. This misconception confuses VPC endpoints for supported AWS services with the need to attach the Lambda function to the VPC.
Visual reference
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.