DVA-C02 Security Practice Question
A developer is tasked with rotating database credentials stored in AWS Secrets Manager for an RDS MySQL instance. The rotation must occur automatically every 30 days. What is the BEST approach?
⚠ Common exam trap
DVA-C02 often tests the misconception that Parameter Store or RDS itself handles credential rotation, when the correct answer is Secrets Manager's built-in rotation Lambda.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure automatic rotation in Secrets Manager using a rotation Lambda function.
Secrets Manager natively supports automatic rotation via a Lambda rotation function, and for RDS MySQL it provides a built-in rotation template that handles the two-step process of creating a new password and updating both the database and the secret. Configuring rotation with a 30-day schedule is a single setting in the console or CLI. This is the purpose-built, lowest-effort solution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Store the credentials in AWS Systems Manager Parameter Store and use a scheduled Lambda to rotate them.
Why it's wrong here
AWS Systems Manager Parameter Store can securely store credentials as SecureString parameters. However, it does not offer built-in, automated rotation capabilities for database credentials. Implementing rotation would require a custom-developed Lambda function to handle the entire lifecycle: generating new credentials, connecting to the database to update them, and then updating the Parameter Store entry, which is a complex and entirely custom solution.
- ✗
Use RDS automatic password rotation and have the application fetch the new password from RDS.
Why it's wrong here
Amazon RDS does not inherently provide an "automatic password rotation" feature that applications can directly query to fetch new credentials. While RDS integrates with AWS Secrets Manager for credential management, the rotation process is orchestrated by Secrets Manager, not the RDS instance itself. An application would typically retrieve credentials from Secrets Manager, not by directly asking the RDS database for a newly rotated password, as such an API does not exist.
- ✗
Use an IAM role for the RDS instance and rotate the role's credentials.
Why it's wrong here
Rotating an IAM role's credentials fails to address the requirement for rotating *database user credentials* within an RDS MySQL instance. IAM roles grant AWS services, like RDS, permissions to access other AWS resources, such as S3 for log exports, not to manage internal database user authentication. Secrets Manager's integrated rotation specifically targets database usernames and passwords. This option is tempting as IAM roles are fundamental for secure AWS access, and an RDS instance *does* utilise roles for service-to-service interactions, but not for its own database user credential lifecycle.
- ✓
Configure automatic rotation in Secrets Manager using a rotation Lambda function.
Why this is correct
AWS Secrets Manager is specifically designed for managing, retrieving, and rotating secrets, including database credentials. It offers a robust, integrated solution for automatic rotation by leveraging a rotation Lambda function. This function, either pre-built by AWS or custom, connects to the database, updates the user's password, and then updates the secret in Secrets Manager, ensuring applications always retrieve the current, rotated credentials securely.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.