Courseiva
Security →hardMultiple Choice

DVA-C02 Security Practice Question

A developer is tasked with rotating database credentials stored in AWS Secrets Manager for an RDS MySQL instance. The rotation must occur automatically every 30 days. What is the BEST approach?

⚠ Common exam trap

DVA-C02 often tests the misconception that Parameter Store or RDS itself handles credential rotation, when the correct answer is Secrets Manager's built-in rotation Lambda.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure automatic rotation in Secrets Manager using a rotation Lambda function.

Secrets Manager natively supports automatic rotation via a Lambda rotation function, and for RDS MySQL it provides a built-in rotation template that handles the two-step process of creating a new password and updating both the database and the secret. Configuring rotation with a 30-day schedule is a single setting in the console or CLI. This is the purpose-built, lowest-effort solution.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Store the credentials in AWS Systems Manager Parameter Store and use a scheduled Lambda to rotate them.

    Why it's wrong here

    AWS Systems Manager Parameter Store can securely store credentials as SecureString parameters. However, it does not offer built-in, automated rotation capabilities for database credentials. Implementing rotation would require a custom-developed Lambda function to handle the entire lifecycle: generating new credentials, connecting to the database to update them, and then updating the Parameter Store entry, which is a complex and entirely custom solution.

  • ✗

    Use RDS automatic password rotation and have the application fetch the new password from RDS.

    Why it's wrong here

    Amazon RDS does not inherently provide an "automatic password rotation" feature that applications can directly query to fetch new credentials. While RDS integrates with AWS Secrets Manager for credential management, the rotation process is orchestrated by Secrets Manager, not the RDS instance itself. An application would typically retrieve credentials from Secrets Manager, not by directly asking the RDS database for a newly rotated password, as such an API does not exist.

  • ✗

    Use an IAM role for the RDS instance and rotate the role's credentials.

    Why it's wrong here

    Rotating an IAM role's credentials fails to address the requirement for rotating *database user credentials* within an RDS MySQL instance. IAM roles grant AWS services, like RDS, permissions to access other AWS resources, such as S3 for log exports, not to manage internal database user authentication. Secrets Manager's integrated rotation specifically targets database usernames and passwords. This option is tempting as IAM roles are fundamental for secure AWS access, and an RDS instance *does* utilise roles for service-to-service interactions, but not for its own database user credential lifecycle.

  • ✓

    Configure automatic rotation in Secrets Manager using a rotation Lambda function.

    Why this is correct

    AWS Secrets Manager is specifically designed for managing, retrieving, and rotating secrets, including database credentials. It offers a robust, integrated solution for automatic rotation by leveraging a rotation Lambda function. This function, either pre-built by AWS or custom, connects to the database, updates the user's password, and then updates the secret in Secrets Manager, ensuring applications always retrieve the current, rotated credentials securely.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.