Store the SaaS client token as a Parameter Store SecureString and retrieve it in Lambda
An Amazon API Gateway API invokes an AWS Lambda function that needs to interact with a software-as-a-service (SaaS) platform. A unique client token is generated in the SaaS platform to grant access to the Lambda function. A security engineer needs to design a solution to encrypt the access token at rest and pass the token to the Lambda function at runtime. Which solution will meet these requirements MOST cost-effectively?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Parameter Store SecureString encrypts the token with KMS and has no per-secret charge, making it the most cost-effective choice (C). Secrets Manager (A) offers rotation/integration features but costs per secret, so it is not the 'most cost-effective' here. A token-based Lambda authorizer (B) validates caller tokens, it does not store the SaaS client token. An environment variable with KMS (D) keeps the token in the function config and risks exposure in logs/configuration. C is correct.
To encrypt a SaaS client token at rest and pass it to a Lambda at runtime most cost-effectively, store it as a SecureString parameter in AWS Systems Manager Parameter Store (which encrypts with KMS and is free to use) and retrieve it via the AWS SDK inside the Lambda function. Secrets Manager (A) does the same but adds per-secret cost, which is unnecessary when cost-effectiveness is the priority.
Choosing Secrets Manager (A)—it meets the requirement but is not the most cost-effective since it bills per secret; Parameter Store SecureString is free. Using a Lambda authorizer (B)—that validates incoming caller tokens, it does not store/retrieve the SaaS client token. Passing the token via an environment variable (D)—it persists the secret in function configuration and can leak into logs.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.