A solutions architect is auditing the security setup of an AWS Lambda function for a company. The Lambda function retrieves the latest changes from an Amazon Aurora database. The Lambda function and the database run in the same VPC. Lambda environment variables are providing the database credentials to the Lambda function.
The Lambda function aggregates data and makes the data available in an Amazon S3 bucket that is configured for server-side encryption with AWS KMS managed encryption keys (SSE-KMS). The data must not travel across the internet. If any database credentials become compromised, the company needs a solution that minimizes the impact of the compromise.
What should the solutions architect recommend to meet these requirements?
Spavanko
Highly Voted 2 years, 5 months agoggrodskiy
Highly Voted 2 years, 4 months agoggrodskiy
Most Recent 2 years, 4 months agosly353
2 years, 5 months agoAmac1979
2 years, 2 months ago