Lambda RDS Private Connectivity Least Overhead
A company uses Amazon RDS to store transactional data. The company runs an RDS DB instance in a private subnet. A developer wrote an AWS Lambda function with default settings to insert, update, or delete data in the DB instance. The developer needs to give the Lambda function the ability to connect to the DB instance privately without using the public internet. Which combination of steps will meet this requirement with the LEAST operational overhead? (Choose two.)
Community Votes
72% of anonymous learners picked answer CD. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests VPC networking integration for serverless functions, where the common trap is over-engineering network paths instead of leveraging shared security group attributes.
Learn how to connect AWS Lambda functions to Amazon RDS privately with minimal operational overhead using shared security groups and subnet configuration.
Many learners choose B because it explicitly allows traffic, but failing to place the Lambda in the same subnet (C) leaves it isolated from the DB's private IP space, requiring NAT or public access.
Community Discussion (18 comments)
- AWS Lambda supports VPC configurations, allowing you to run Lambda functions within your own VPC. This enables private connectivity between Lambda functions and resources within the VPC, such as RDS DB instances. Reference AWS Lambda documentation on VPC configurations: [AWS Lambda VPC Settings]https://docs.aws.amazon.com/lambda/latest/dg/configuration-vpc.html - AWS security groups provide a flexible and scalable way to control traffic to your instances or resources. By attaching the same security group to both the Lambda function and the RDS DB instance, you can ensure they share the same set of rules for inbound and outbound traffic. - Self-referencing rules within security groups enable instances within the same security group to communicate with each other over specified ports. - Reference AWS documentation on security groups and self-referencing rules: [Security Groups for Your VPC]https://docs.aws.amazon.com/vpc/latest/userguide/VPC_SecurityGroups.html
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
To connect a Lambda function to an RDS instance privately, both resources must reside within the same VPC and be able to reach each other via their private IPs. Option C places the Lambda in the same subnet as the DB, ensuring direct Layer 3 connectivity without needing a NAT Gateway or Public Internet. Option D attaches the same Security Group to both, using a self-referencing rule to allow inbound database port traffic from the Lambda. This combination provides the LEAST operational overhead because it avoids complex route table modifications, NAT gateways, or managing separate SGs.Why the Other Options Are Wrong
Option A exposes the DB to the internet, violating the "privately" requirement. Option B updates the DB's SG but doesn't ensure the Lambda can reach the DB's private IP if they are in different subnets/VPCs; without Option C, the connection fails. Option E modifies Network ACLs, which are stateless and less granular than SGs, adding unnecessary complexity. Sharing SGs (D) is acceptable for this specific exam scenario to minimize overhead, despite general best practices suggesting distinct SGs.Community Comment Notes
Several users noted that Option B alone is insufficient because it doesn't address the network path. As user Alagong pointed out, "this solution only modifies the inbound rules... does not facilitate a private connection." Others debated whether sharing SGs (D) is bad practice, but for "least operational overhead," it is the intended answer in this context. User certplan highlighted that C enables communication within the same network, eliminating public internet need.Exam Strategy
When asked for 'least operational overhead' in AWS networking questions, look for solutions that leverage existing infrastructure attributes (like shared Security Groups or same-subnet placement) rather than adding new components like NAT Gateways or Transit Gateways.
Frequently Asked Questions
Why is Option B incorrect for private connectivity?
Option B only opens the DB port but doesn't ensure the Lambda function is in the same VPC/subnet to reach the private IP. Without C, the Lambda might still need public routing.
Is sharing Security Groups between Lambda and RDS safe?
While distinct SGs are better for strict isolation, the exam prioritizes 'least operational overhead'. Sharing an SG with a self-referencing rule is the simplest way to meet the connectivity requirement here.
Related Analysis
Practice All DEA-C01 Questions
Access 100 questions with complete answers and detailed explanations.
View Full DEA-C01 Practice Test →