Question 1 · choose 1
An AWS Lambda function connects to an Amazon RDS for PostgreSQL database with a password stored in a plain environment variable. A security review requires the password to change automatically every 30 days without redeploying the function, and the function must not call a secrets API on every invocation. What should the developer do?
- AStore the password as a SecureString parameter and change it with a scheduled script
- BSecrets Manager with rotation, read through the Lambda extension's cache
- CEncrypt the environment variable with a customer managed key that rotates every 30 days
- DPut the password in the deployment package and redeploy the function every 30 days
Show the answer and why
AStore the password as a SecureString parameter and change it with a scheduled script
Incorrect
Parameter Store has no credential rotation. The script would also have to change the password in the database, which is the work rotation does for you.
BSecrets Manager with rotation, read through the Lambda extension's cache
Correct
Secrets Manager rotates the secret in both the secret and the database on a schedule, and the extension retrieves and caches the secret so the function does not call the API each time.
CEncrypt the environment variable with a customer managed key that rotates every 30 days
Incorrect
Rotating the KMS key changes the key that protects the variable. The database password itself stays the same.
DPut the password in the deployment package and redeploy the function every 30 days
Incorrect
Hard-coded credentials require redeploying for every change, which is what Secrets Manager's runtime retrieval and rotation avoid.
Rotation belongs to Secrets Manager; caching through the Lambda extension keeps per-invocation API calls down.
AWS documentation