How to encrypt Lambda environment variables using AWS KMS?

A company has an application that uses an AWS Lambda function to process data. A developer must implement encryption in transit for all sensitive configuration data, such as API keys, that is stored in the application. The developer creates an AWS Key Management Service (AWS KMS) customer managed key. What should the developer do next to meet the encryption requirement?

  1. Create parameters of the String type in AWS Systems Manager Parameter Store. For each parameter, specify the KMS key ID to encrypt the parameter in transit. Reference the GetParameter API call in the Lambda environment variables.
  2. Create secrets in AWS Secrets Manager by using the customer managed KMS key. Create a new Lambda function and set up a Lambda layer. Configure the Lambda layer to retrieve the values from Secrets Manager.
  3. Create objects in Amazon S3 for each sensitive data field. Specify the customer managed KMS key to encrypt the object. Configure the Lambda function to retrieve the objects from Amazon S3 during data processing.
  4. Create encrypted Lambda environment variables. Specify the customer managed KMS key to encrypt the variables. Enable encryption helpers for encryption in transit. Grant permission to the Lambda function's execution role to access the KMS key. Source Reference Answer

Community Votes

D
82%
B
18%

82% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests understanding of Lambda environment variable encryption helpers and the distinction between encryption at rest and encryption in transit for configuration data stored within the Lambda service itself.

This question tests the implementation of encryption in transit for sensitive configuration data in AWS Lambda using AWS KMS customer managed keys. The community consensus heavily favors using encrypted Lambda environment variables with KMS as the most direct and AWS-native approach.

Many candidates choose AWS Secrets Manager (Option B) because it is a popular service for managing secrets, but the question specifically asks about data 'stored in the application' and encryption in transit, making Lambda environment variables with KMS the correct choice.

Community Discussion (6 comments)

cachac 👍 8 Selected: D
Considering: "API keys, that is stored in the application". D is the most direct approach. Lambda supports encrypting environment variables with a KMS key, eliminating the need for additional services or layers.
lak_83 👍 1 Selected: B
Answer is B and it does provide more flexibility than D
bp07 👍 1 Selected: A
I feel it should be A. D can't be used as this approach does not use encryption in transit when retrieving sensitive data, as the data is embedded directly in the Lambda configuration.
CloudChingon 👍 1 Selected: B
AWS Secret Manager and pulling the secrets from it using layers sounds reasonable to me. I have seen that implementation in real life.
preachr 👍 1 Selected: D
https://docs.aws.amazon.com/lambda/latest/dg/configuration-envvars-encryption.html
tomchandler077 👍 1
OPTION B ---CORRECT . To meet the requirement of encrypting sensitive configuration data in transit while using it within an AWS Lambda function, the developer should leverage AWS Secrets Manager. Secrets Manager is specifically designed for handling and securing sensitive information like API keys, database credentials, and similar data, making it suitable for this scenario.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Understanding Lambda Environment Variable Encryption

The correct answer is D because it directly addresses the requirement to encrypt sensitive configuration data that is "stored in the application" using encryption in transit with a customer managed KMS key.

Why Option D is Correct:

AWS Lambda supports encryption helpers for environment variables, which provide encryption in transit when the Lambda service retrieves and decrypts these variables. When you specify a customer managed KMS key for environment variable encryption:

  • The variables are encrypted at rest using the KMS key
  • Encryption helpers ensure that when Lambda retrieves these variables during execution, they are transmitted securely (encryption in transit)
  • The Lambda execution role must have permission to use the KMS key for decryption
  • This approach keeps sensitive data within the Lambda service without requiring additional infrastructure
Why Other Options Are Incorrect:

Option A is incorrect because AWS Systems Manager Parameter Store's String type parameters don't inherently provide encryption in transit in the way the question requires. While SecureString parameters use KMS, the question specifically mentions data "stored in the application," pointing to Lambda's native capabilities.

Option B is incorrect because while AWS Secrets Manager is excellent for managing secrets, the question asks about data already "stored in the application." Creating a Lambda layer to retrieve secrets adds unnecessary complexity and doesn't directly address encrypting data that's already part of the Lambda configuration.

Option C is incorrect because storing individual sensitive fields as S3 objects is an anti-pattern for configuration data. S3 is designed for object storage, not for managing application configuration or secrets, and this approach would significantly increase latency and complexity.

Key Distinction:

The phrase "stored in the application" is crucial. It indicates the data should remain within Lambda's configuration (environment variables) rather than being externalized to another service. Lambda's built-in encryption helpers with KMS provide the encryption in transit requirement without architectural changes.

Official Reference

Exam Strategy

When you see 'stored in the application' in Lambda questions, think about Lambda's native capabilities first (environment variables, layers) before considering external services. Look for the simplest solution that meets all requirements without adding unnecessary complexity.

Related Analysis

Practice All DVA-C02 Questions

Access 100 questions with complete answers and detailed explanations.

View Full DVA-C02 Practice Test →

← Back to DVA-C02 Study Guide