How to encrypt Lambda environment variables using AWS KMS?
A company has an application that uses an AWS Lambda function to process data. A developer must implement encryption in transit for all sensitive configuration data, such as API keys, that is stored in the application. The developer creates an AWS Key Management Service (AWS KMS) customer managed key. What should the developer do next to meet the encryption requirement?
Community Votes
82% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests understanding of Lambda environment variable encryption helpers and the distinction between encryption at rest and encryption in transit for configuration data stored within the Lambda service itself.
This question tests the implementation of encryption in transit for sensitive configuration data in AWS Lambda using AWS KMS customer managed keys. The community consensus heavily favors using encrypted Lambda environment variables with KMS as the most direct and AWS-native approach.
Many candidates choose AWS Secrets Manager (Option B) because it is a popular service for managing secrets, but the question specifically asks about data 'stored in the application' and encryption in transit, making Lambda environment variables with KMS the correct choice.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Understanding Lambda Environment Variable Encryption
The correct answer is D because it directly addresses the requirement to encrypt sensitive configuration data that is "stored in the application" using encryption in transit with a customer managed KMS key.
Why Option D is Correct:
AWS Lambda supports encryption helpers for environment variables, which provide encryption in transit when the Lambda service retrieves and decrypts these variables. When you specify a customer managed KMS key for environment variable encryption:
- The variables are encrypted at rest using the KMS key
- Encryption helpers ensure that when Lambda retrieves these variables during execution, they are transmitted securely (encryption in transit)
- The Lambda execution role must have permission to use the KMS key for decryption
- This approach keeps sensitive data within the Lambda service without requiring additional infrastructure
Option A is incorrect because AWS Systems Manager Parameter Store's String type parameters don't inherently provide encryption in transit in the way the question requires. While SecureString parameters use KMS, the question specifically mentions data "stored in the application," pointing to Lambda's native capabilities.
Option B is incorrect because while AWS Secrets Manager is excellent for managing secrets, the question asks about data already "stored in the application." Creating a Lambda layer to retrieve secrets adds unnecessary complexity and doesn't directly address encrypting data that's already part of the Lambda configuration.
Option C is incorrect because storing individual sensitive fields as S3 objects is an anti-pattern for configuration data. S3 is designed for object storage, not for managing application configuration or secrets, and this approach would significantly increase latency and complexity.
Key Distinction:
The phrase "stored in the application" is crucial. It indicates the data should remain within Lambda's configuration (environment variables) rather than being externalized to another service. Lambda's built-in encryption helpers with KMS provide the encryption in transit requirement without architectural changes.
Official Reference
Exam Strategy
When you see 'stored in the application' in Lambda questions, think about Lambda's native capabilities first (environment variables, layers) before considering external services. Look for the simplest solution that meets all requirements without adding unnecessary complexity.
Related Analysis
Practice All DVA-C02 Questions
Access 100 questions with complete answers and detailed explanations.
View Full DVA-C02 Practice Test →