Q35Data Operations and SupportMultiple answers
A company uses Amazon RDS to store transactional data. The company runs an RDS DB instance in a private subnet. A developer wrote an AWS Lambda function with default settings to insert, update, or delete data in the DB instance. The developer needs to give the Lambda function the ability to connect to the DB instance privately without using the public internet. Which combination of steps will meet this requirement with the LEAST operational overhead? (Choose two.)
Select 2 answers.
← → navigate · a answer
Community votes
Discussion · 19
C, D 7
Selected Answer: CD
This option only changes the inbound rules on the security group of the DB instance, but it does not change the outbound rules on the security group of the Lambda function. Also, this option does not provide a private connection from the Lambda function to the DB instance, so the Lambda function would still have to use the public internet to reach the DB instance. Therefore, this option does not meet the requirement.
4
So, there coudl be a justified argument for the following:
C. Configure the Lambda function to run in the same subnet that the DB instance uses:
By running the Lambda function in the same subnet as the RDS DB instance, you enable them to communicate privately within the same network, removing the need for public internet access and lowering operational overhead.
D. Attach the same security group to the Lambda function and the DB instance. Include a self-referencing rule that allows access through the database port:
By attaching the same security group to both the Lambda function and the RDS DB instance, and including a self-referencing rule that allows access through the database port, you ensure secure communication between them within the same VPC without exposing the database to the public internet. This approach reduces operational overhead by centralizing security management and simplifying access control.
C, D 4
Selected Answer: CD
B: need update security group. and there there may be other application need to access db except for lambda function
D: it works and reuse security group which has less operational overhead
B, D 3
Selected Answer: BD
bbb ddd
2
The phrase "Include a self-referencing rule that allows access through the database port" means configuring the security group associated with the resources (in this case, the Lambda function and the RDS DB instance) to allow inbound traffic from the resources themselves on a specific port, typically the port used for database communication.
In AWS security groups, a self-referencing rule means allowing traffic from the security group itself. This setup is often used to make communication possible between resources in the same security group or VPC without having to specify individual IP addresses.
2
A is not an option as it exposes the data to public
B is not an option as we don't want the lambda to be the only entity accessing the db, there can be many other apps. doing this is not scalable
C, D 2
Selected Answer: CD
I would go with CD, since it seems like less operational effort, in my opinion
2
While putting the Lambda function in the same subnet as the DB instance would technically let them communicate privately within the same network, it adds extra complexity and operational overhead. Lambda functions usually run in AWS-managed VPCs, and configuring them to run in a specific subnet might need manual intervention and ongoing maintenance.
2
Moreover, running a Lambda function inside a subnet does not by itself guarantee private connectivity to the RDS instance. Extra networking setup would still be required to let the Lambda function access the RDS instance securely, such as configuring the right security groups and possibly adjusting network ACLs.
Hence C can't be the answer
C, D 2
Selected Answer: CD
I will go with C and D on this one, because in my opinion B is not phrased correctly.
The correct way to phrase it would be something like:
Update the security group of the RDS instance to allow inbound traffic on the database port (3306) only from the security group associated with the Lambda function.
B, C 2
Selected Answer: BC
D is wrong. It is bad security practice for a DB to share SG with the client.
C is correct compared to the other opinions (A & E).
1
what does "Include a self-referencing rule that allows access through the database port." mean?
B, C 1
Selected Answer: BC
When you want Lambda to "privately" connect to a resource (RDS in this case) that sits inside a VPC, then you deploy Lambda inside VPC. = C
Then you attach a proper IAM role to lambda.
Then, to be more secure you open the RDS security group only on the specific port:
MySQL/Aurora MySQL: 3306
SQL Server: 1433
PostgreSQL: 5432
Oracle: 1521
1
Here's how you would implement this:
1. **Attach the same security group to both the Lambda function and the RDS DB instance**: Make sure both resources are associated with the same security group.
2. **Create an inbound rule in the security group**: Set up the security group to allow inbound traffic on the database port (e.g., 3306 for MySQL) from the security group itself.
For example, if the security group ID is sg-1234567890 and the database port is 3306, the inbound rule would look something like this:
Type: Custom TCP Rule
Protocol: TCP
Port Range: 3306 (or the port your database uses)
Source: sg-1234567890 (the security group ID itself)
This rule lets the Lambda function, which is also part of the same security group, communicate with the RDS DB instance through the specified port. It effectively creates a loopback or self-referencing rule within the security group, allowing internal communication between resources while keeping security boundaries intact.
1
- AWS Lambda supports VPC configurations, which let you run Lambda functions inside your own VPC. This enables private connectivity between Lambda functions and resources within the VPC, such as RDS DB instances.
Reference AWS Lambda documentation on VPC configurations: [AWS Lambda VPC Settings]https://docs.aws.amazon.com/lambda/latest/dg/configuration-vpc.html
- AWS security groups provide a flexible and scalable way to control traffic to your instances or resources. By attaching the same security group to both the Lambda function and the RDS DB instance, you can make sure they share the same set of rules for inbound and outbound traffic.
- Self-referencing rules within security groups allow instances within the same security group to communicate with each other over specified ports.
- Reference AWS documentation on security groups and self-referencing rules: [Security Groups for Your VPC]https://docs.aws.amazon.com/vpc/latest/userguide/VPC_SecurityGroups.html
1
B. - While updating the security group of the DB instance to allow only Lambda function invocations on the database port may look like a viable solution, it's not the most efficient approach. This option misses the need for the Lambda function to communicate securely with the DB instance within the same VPC/subnet.
- Reference: [Amazon RDS documentation on security groups](https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/USER_WorkingWithSecurityGroups.html)
1
Thank you. You always help me solve my problems.
B, D 1
Selected Answer: BD
B & D
C is wrong
If you want the Lambda function to access the RDS instance privately, it does not need to run in the same subnet. As long as both are in the same VPC, the Lambda function can connect.
B, D 1
Selected Answer: BD
I would choose B & D. In my opinion, C would add operational overhead.