DOP-C02 Security and Compliance Practice Question
A company has a Lambda function that processes sensitive data and needs to access an RDS database. The security team requires that the database credentials are automatically rotated every 30 days. Which service should be used to store and rotate the credentials?
⚠ Common exam trap
It's easy for candidates to confuse AWS Systems Manager Parameter Store with Secrets Manager because both can store secrets, but Parameter Store lacks native automatic rotation and RDS integration, making it unsuitable for the 30-day rotation requirement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Secrets Manager
AWS Secrets Manager is the correct choice because it is specifically designed to securely store, manage, and automatically rotate database credentials for services like RDS. It supports native, built-in rotation for Amazon RDS (MySQL, PostgreSQL, Oracle, SQL Server, and MariaDB) without requiring custom Lambda functions. The automatic rotation can be scheduled at a desired interval (e.g., every 30 days) using a rotation schedule defined in the secret's configuration, and it integrates directly with RDS to update the credentials on both the secret and the database.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS Secrets Manager
Why this is correct
AWS Secrets Manager is a purpose-built service for storing and managing database credentials and other sensitive secrets. It provides native automatic rotation, including native integration with Amazon RDS, Redshift, and DocumentDB, which enforces credential lifecycle management and reduces the operational burden of periodic rotation. Its resource-based policies and tight integration with AWS Lambda and IAM make it the correct, secure choice for handling sensitive data.
- ✗
AWS Systems Manager Parameter Store
Why it's wrong here
AWS Systems Manager Parameter Store can store secrets as SecureString values encrypted with KMS, but it does not provide automatic rotation out of the box. You would need to build a custom rotation mechanism, often using AWS Lambda, which adds complexity and risk of inconsistent rotation. Parameter Store is better suited for configuration parameters, non-sensitive data, or secrets that can tolerate manual rotation, making it less robust than Secrets Manager for sensitive database credentials.
- ✗
Amazon DynamoDB
Why it's wrong here
Amazon DynamoDB is a fully managed NoSQL database designed for scalable, low-latency application data storage, not a secrets management service. Storing database credentials in DynamoDB forces you to implement your own encryption, access control, rotation, and audit logging, which is error-prone and lacks AWS-native lifecycle management. It is a poor choice for sensitive data because it does not offer built-in rotation or secret versioning, and integrating it with Lambda would require significant custom development.
- ✗
AWS IAM roles
Why it's wrong here
AWS IAM roles are an identity and access management construct that grants permissions to AWS principals, such as users, services, or Lambda functions, via temporary credentials. They do not store the secret values themselves; rather, they can enable IAM database authentication, which lets applications authenticate to supported AWS databases without retrieving a stored password. However, for the explicit purpose of storing sensitive data such as database credentials, IAM roles are not a storage service and cannot hold the secret content, making them an incorrect answer.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on DOP-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company requires that all secrets (e.g., database passwords) used by Lambda functions be rotated automatically every 30 days. Which combination of services should be used?
hard- A.AWS CloudHSM and AWS Lambda
- ✓ B.AWS Secrets Manager and AWS Lambda
- C.AWS Systems Manager Parameter Store and AWS Lambda
- D.AWS KMS and AWS Lambda
Why B: AWS Secrets Manager is the correct choice because it natively supports automatic secret rotation on a configurable schedule (e.g., every 30 days) using a Lambda function as the rotation handler. Secrets Manager directly integrates with Lambda to invoke the rotation logic, updating the secret value and propagating the change to the target database or service without custom infrastructure. CloudHSM, Parameter Store, and KMS do not provide built-in, scheduled rotation of secrets with automatic Lambda invocation.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.