Add an interface VPC endpoint for Secrets Manager

Answer Correct answer: C — an interface VPC endpoint for Secrets Manager keeps Lambda-to-Secrets-Manager traffic private and off the internet.

A company has a VPC that has no internet access and has the private DNS hostnames option enabled. An Amazon Aurora database is running inside the VPC. A security engineer wants to use AWS Secrets Manager to automatically rotate the credentials for the Aurora database. The security engineer configures the Secrets Manager default AWS Lambda rotation function to run inside the same VPC that the Aurora database uses. However, the security engineer determines that the password cannot be rotated properly because the Lambda function cannot communicate with the Secrets Manager endpoint. What is the MOST secure way that the security engineer can give the Lambda function the ability to communicate with the Secrets Manager endpoint?

  1. Add a NAT gateway to the VPC to allow access to the Secrets Manager endpoint.
  2. Add a gateway VPC endpoint to the VPC to allow access to the Secrets Manager endpoint.
  3. Add an interface VPC endpoint to the VPC to allow access to the Secrets Manager endpoint. Correct Answer
  4. Add an internet gateway for the VPC to allow access to the Secrets Manager endpoint.

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Secrets Manager is reached via an interface (PrivateLink) endpoint, not a gateway endpoint. An interface endpoint gives private DNS and keeps Lambda-to-Secrets-Manager traffic off the public internet—the most secure option. A NAT gateway (A) or internet gateway (D) would route through the internet and contradict the no-internet design; a gateway endpoint (B) is for S3/DynamoDB and does not serve Secrets Manager. C is correct.

In a VPC with no internet, a Secrets Manager rotation Lambda in the VPC cannot reach the Secrets Manager endpoint. The most secure fix is an interface VPC endpoint (PrivateLink) for Secrets Manager, which keeps traffic on the AWS private network without needing internet, NAT, or an internet gateway. A gateway endpoint exists for S3/DynamoDB, not Secrets Manager; NAT/internet gateway would expose the VPC to the internet.

Choosing a gateway VPC endpoint (B)—gateway endpoints support only S3 and DynamoDB, not Secrets Manager. Choosing NAT/internet gateway (A/D)—they introduce internet routing, which is less secure and conflicts with the no-internet VPC. Interface endpoint (C) is the private, purpose-built path.

Community Discussion (3 comments)

NimiBes 👍 1 Selected: C
I think C
jade290 👍 4 Selected: C
"You can establish a private connection between your VPC and Secrets Manager by creating an interface VPC endpoint." https://docs.aws.amazon.com/secretsmanager/latest/userguide/vpc-endpoint-overview.html
Zek 👍 4
C Similar quesstion: https://docs.aws.amazon.com/secretsmanager/latest/userguide/vpc-endpoint-overview.html

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Secrets Manager is accessed through an interface (PrivateLink) VPC endpoint, which creates a private ENI with private DNS inside the VPC so the Lambda function reaches the service entirely on the AWS network—no internet, NAT, or internet gateway required. This is the most secure way to satisfy the no-internet design.

Why the Other Options Are Wrong

B (gateway endpoint) supports only S3 and DynamoDB, not Secrets Manager. A (NAT gateway) and D (internet gateway) route traffic to the public internet, which is less secure and violates the no-internet VPC. C is the private, purpose-built solution.

Community Comment Notes

Community voted C (100). Commenters quoted AWS docs: establish a private connection to Secrets Manager by creating an interface VPC endpoint. B was excluded as gateway endpoints do not cover Secrets Manager. C confirmed.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide