QuestionQ9

Security

A company is using Amazon OpenSearch Service to implement an audit monitoring system. A developer needs to create an AWS CloudFormation custom resource that is associated with an AWS Lambda function to configure the OpenSearch Service domain. The Lambda function must access the OpenSearch Service domain by using OpenSearch Service internal master user credentials.

What is the MOST secure way to pass these credentials to the Lambda function?

Explanation

AWS Secrets Manager with a CloudFormation dynamic reference is the most secure pattern. The secret is stored encrypted; Lambda retrieves it at runtime using an IAM role with secretsmanager:GetSecretValue permissions; and the secret name is stored as an environment variable to avoid hardcoding. This approach follows AWS best practices for credential management, supports rotation, and avoids exposure in code or deployment logs. Other options risk exposing credentials in CloudFormation or parameter stores.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!