Courseiva
Security →hardMultiple Choice

DVA-C02 Security Practice Question

A developer is deploying an application on Amazon EC2 that needs to access an Amazon RDS database. The security team requires that database credentials are automatically rotated every 30 days and that the application retrieves them securely. Which solution should the developer implement?

⚠ Common exam trap

The trap here is assuming Parameter Store offers automatic rotation for RDS; it does not, and custom rotation is required, which is not the best practice.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use AWS Secrets Manager to store the database credentials and configure automatic rotation using the built-in RDS rotation function.

AWS Secrets Manager provides native support for rotating RDS database credentials using a Lambda rotation function. It automatically updates the password in both the database and the secret, and the application retrieves the current credentials via API. This satisfies the rotation and secure retrieval requirements with minimal custom code.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create an IAM database authentication token for RDS and configure the application to generate a new token every 30 days.

    Why it's wrong here

    IAM database authentication for RDS uses short-lived authentication tokens (valid for 15 minutes) and does not manage database user credentials. It does not rotate passwords. While it eliminates password management, it requires application code changes and does not provide a 30-day rotation of credentials as specified.

  • ✗

    Store the database credentials in AWS Systems Manager Parameter Store as a SecureString parameter and enable automatic rotation using a Lambda function.

    Why it's wrong here

    Parameter Store SecureString can store encrypted data, but it does not provide built-in automatic rotation for RDS credentials. You would have to implement custom rotation logic, which is complex and error-prone. AWS Secrets Manager offers native rotation for RDS databases, making it the better choice for this requirement.

  • ✓

    Use AWS Secrets Manager to store the database credentials and configure automatic rotation using the built-in RDS rotation function.

    Why this is correct

    AWS Secrets Manager is designed for managing and rotating secrets. It provides built-in integration with Amazon RDS to automatically rotate credentials on a schedule. The application can retrieve the current credentials using the Secrets Manager API or SDK, ensuring secure access. This meets both the rotation and secure retrieval requirements.

  • ✗

    Store the credentials in an encrypted Amazon S3 object and use an S3 event notification to trigger a Lambda function that rotates the password every 30 days.

    Why it's wrong here

    Storing credentials in S3, even encrypted, is not a secure best practice for secrets management. Implementing rotation via S3 events and Lambda requires custom development and lacks the built-in integration and auditing that Secrets Manager provides. This approach increases complexity and risk.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

Courseiva writes every DVA-C02 question from scratch — 1,135 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.