Add an interface VPC endpoint for Secrets Manager
A company has a VPC that has no internet access and has the private DNS hostnames option enabled. An Amazon Aurora database is running inside the VPC. A security engineer wants to use AWS Secrets Manager to automatically rotate the credentials for the Aurora database. The security engineer configures the Secrets Manager default AWS Lambda rotation function to run inside the same VPC that the Aurora database uses. However, the security engineer determines that the password cannot be rotated properly because the Lambda function cannot communicate with the Secrets Manager endpoint. What is the MOST secure way that the security engineer can give the Lambda function the ability to communicate with the Secrets Manager endpoint?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Secrets Manager is reached via an interface (PrivateLink) endpoint, not a gateway endpoint. An interface endpoint gives private DNS and keeps Lambda-to-Secrets-Manager traffic off the public internet—the most secure option. A NAT gateway (A) or internet gateway (D) would route through the internet and contradict the no-internet design; a gateway endpoint (B) is for S3/DynamoDB and does not serve Secrets Manager. C is correct.
In a VPC with no internet, a Secrets Manager rotation Lambda in the VPC cannot reach the Secrets Manager endpoint. The most secure fix is an interface VPC endpoint (PrivateLink) for Secrets Manager, which keeps traffic on the AWS private network without needing internet, NAT, or an internet gateway. A gateway endpoint exists for S3/DynamoDB, not Secrets Manager; NAT/internet gateway would expose the VPC to the internet.
Choosing a gateway VPC endpoint (B)—gateway endpoints support only S3 and DynamoDB, not Secrets Manager. Choosing NAT/internet gateway (A/D)—they introduce internet routing, which is less secure and conflicts with the no-internet VPC. Interface endpoint (C) is the private, purpose-built path.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.