Store the SaaS client token as a Parameter Store SecureString and retrieve it in Lambda

Answer Correct answer: C — store the token as a Parameter Store SecureString and retrieve it in Lambda, the most cost-effective encrypted option.

An Amazon API Gateway API invokes an AWS Lambda function that needs to interact with a software-as-a-service (SaaS) platform. A unique client token is generated in the SaaS platform to grant access to the Lambda function. A security engineer needs to design a solution to encrypt the access token at rest and pass the token to the Lambda function at runtime. Which solution will meet these requirements MOST cost-effectively?

  1. Store the client token as a secret in AWS Secrets Manager. Use the AWS SDK to retrieve the secret in the Lambda function.
  2. Configure a token-based Lambda authorizer in API Gateway.
  3. Store the client token as a SecureString parameter in AWS Systems Manager Parameter Store. Use the AWS SDK to retrieve the value of the SecureString parameter in the Lambda function. Correct Answer
  4. Use AWS Key Management Service (AWS KMS) to encrypt the client token. Pass the token to the Lambda function at runtime through an environment variable.

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Parameter Store SecureString encrypts the token with KMS and has no per-secret charge, making it the most cost-effective choice (C). Secrets Manager (A) offers rotation/integration features but costs per secret, so it is not the 'most cost-effective' here. A token-based Lambda authorizer (B) validates caller tokens, it does not store the SaaS client token. An environment variable with KMS (D) keeps the token in the function config and risks exposure in logs/configuration. C is correct.

To encrypt a SaaS client token at rest and pass it to a Lambda at runtime most cost-effectively, store it as a SecureString parameter in AWS Systems Manager Parameter Store (which encrypts with KMS and is free to use) and retrieve it via the AWS SDK inside the Lambda function. Secrets Manager (A) does the same but adds per-secret cost, which is unnecessary when cost-effectiveness is the priority.

Choosing Secrets Manager (A)—it meets the requirement but is not the most cost-effective since it bills per secret; Parameter Store SecureString is free. Using a Lambda authorizer (B)—that validates incoming caller tokens, it does not store/retrieve the SaaS client token. Passing the token via an environment variable (D)—it persists the secret in function configuration and can leak into logs.

Community Discussion (3 comments)

phmeeeee 👍 1 Selected: C
C - ParameterStore with SecureString is free. If the question asking more secure I will prefer SecretManager (which is not in the case)
Pmktechno 👍 2 Selected: C
SecureString is FREE
Bad_Mat 👍 1
Should be C

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

AWS Systems Manager Parameter Store SecureString encrypts the token at rest with KMS and is offered at no per-secret cost, so retrieving it in the Lambda via the SDK meets the encryption-at-rest and runtime-pass requirements most cost-effectively. It avoids the recurring per-secret charges of Secrets Manager while still using KMS for encryption.

Why the Other Options Are Wrong

A (Secrets Manager) satisfies the functional need but incurs per-secret costs, so it is not the most cost-effective choice the question asks for. B (token-based Lambda authorizer) is for authenticating callers to API Gateway, not for storing the SaaS client token. D passes the token via an environment variable, which persists the secret in function configuration and can surface in logs. C is correct.

Community Comment Notes

Community voted C (100). Commenters stressed SecureString in Parameter Store is free, whereas Secrets Manager would be preferred only if more security features were required—not the case here. C confirmed as most cost-effective.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide