New Year Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Amazon Web Services AWS Certified Security – Specialty SCS-C03 Question # 7 Topic 1 Discussion

Amazon Web Services AWS Certified Security – Specialty SCS-C03 Question # 7 Topic 1 Discussion

SCS-C03 Exam Topic 1 Question 7 Discussion:
Question #: 7
Topic #: 1

A company has a VPC that has no internet access and has the private DNS hostnames option enabled. An Amazon Aurora database is running inside the VPC. A security engineer wants to use AWS Secrets Manager to automatically rotate the credentials for the Aurora database. The security engineer configures the Secrets Manager default AWS Lambda rotation function to run inside the same VPC that the Aurora database uses. However, the security engineer determines that the password cannot be rotated properly because the Lambda function cannot communicate with the Secrets Manager endpoint.

What is the MOST secure way that the security engineer can give the Lambda function the ability to communicate with the Secrets Manager endpoint?


A.

Add a NAT gateway to the VPC to allow access to the Secrets Manager endpoint.


B.

Add a gateway VPC endpoint to the VPC to allow access to the Secrets Manager endpoint.


C.

Add an interface VPC endpoint to the VPC to allow access to the Secrets Manager endpoint.


D.

Add an internet gateway for the VPC to allow access to the Secrets Manager endpoint.


Get Premium SCS-C03 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.