Courseiva

CCSP Cloud Platform and Infrastructure Security Practice Question

A serverless function needs to access a private RDS database inside a VPC. What configuration is required to enable this without using public IP addresses?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Place the Lambda function inside the VPC using VPC configuration

Serverless functions can be configured with VPC integration to access resources inside a VPC via private IP.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Store database credentials in the function code

    Why it's wrong here

    Hardcoding credentials in function code exposes secrets in source control and logs, and grants no network path to a private RDS instance. It is tempting as a quick way to supply authentication, but credential storage belongs in AWS Secrets Manager or Parameter Store, not the deployment package.

  • ✗

    Use a NAT Gateway to allow inbound traffic

    Why it's wrong here

    A NAT Gateway translates outbound traffic from private subnets to the internet; it does not accept inbound connections, so it cannot reach RDS. It is correct when private instances need outbound internet access, such as patching, not for enabling a Lambda function to connect inward to a database.

  • ✓

    Place the Lambda function inside the VPC using VPC configuration

    Why this is correct

    Placing the Lambda function inside the VPC via VPC configuration gives it an elastic network interface in a private subnet, allowing it to reach the RDS instance over private IP addresses. No public IP or internet gateway is required for the database connection.

  • ✗

    Attach an Internet Gateway to the VPC

    Why it's wrong here

    An Internet Gateway provides bidirectional public connectivity for subnets, contradicting the requirement to avoid public IP addresses and exposing RDS. It is the right component when resources must be publicly reachable, whereas private RDS access from Lambda requires VPC configuration and security group rules instead.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.