CCSP Cloud Platform and Infrastructure Security Practice Question
A serverless function needs to access a private RDS database inside a VPC. What configuration is required to enable this without using public IP addresses?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Place the Lambda function inside the VPC using VPC configuration
Serverless functions can be configured with VPC integration to access resources inside a VPC via private IP.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Store database credentials in the function code
Why it's wrong here
Hardcoding credentials in function code exposes secrets in source control and logs, and grants no network path to a private RDS instance. It is tempting as a quick way to supply authentication, but credential storage belongs in AWS Secrets Manager or Parameter Store, not the deployment package.
- ✗
Use a NAT Gateway to allow inbound traffic
Why it's wrong here
A NAT Gateway translates outbound traffic from private subnets to the internet; it does not accept inbound connections, so it cannot reach RDS. It is correct when private instances need outbound internet access, such as patching, not for enabling a Lambda function to connect inward to a database.
- ✓
Place the Lambda function inside the VPC using VPC configuration
Why this is correct
Placing the Lambda function inside the VPC via VPC configuration gives it an elastic network interface in a private subnet, allowing it to reach the RDS instance over private IP addresses. No public IP or internet gateway is required for the database connection.
- ✗
Attach an Internet Gateway to the VPC
Why it's wrong here
An Internet Gateway provides bidirectional public connectivity for subnets, contradicting the requirement to avoid public IP addresses and exposing RDS. It is the right component when resources must be publicly reachable, whereas private RDS access from Lambda requires VPC configuration and security group rules instead.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.