Courseiva
Security and Compliance →hardMultiple Choice

DOP-C02 Security and Compliance Practice Question

A company has a Lambda function that processes sensitive data and needs to access an RDS database. The security team requires that the database credentials are automatically rotated every 30 days. Which service should be used to store and rotate the credentials?

⚠ Common exam trap

It's easy for candidates to confuse AWS Systems Manager Parameter Store with Secrets Manager because both can store secrets, but Parameter Store lacks native automatic rotation and RDS integration, making it unsuitable for the 30-day rotation requirement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Secrets Manager

AWS Secrets Manager is the correct choice because it is specifically designed to securely store, manage, and automatically rotate database credentials for services like RDS. It supports native, built-in rotation for Amazon RDS (MySQL, PostgreSQL, Oracle, SQL Server, and MariaDB) without requiring custom Lambda functions. The automatic rotation can be scheduled at a desired interval (e.g., every 30 days) using a rotation schedule defined in the secret's configuration, and it integrates directly with RDS to update the credentials on both the secret and the database.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    AWS Secrets Manager

    Why this is correct

    AWS Secrets Manager is a purpose-built service for storing and managing database credentials and other sensitive secrets. It provides native automatic rotation, including native integration with Amazon RDS, Redshift, and DocumentDB, which enforces credential lifecycle management and reduces the operational burden of periodic rotation. Its resource-based policies and tight integration with AWS Lambda and IAM make it the correct, secure choice for handling sensitive data.

  • ✗

    AWS Systems Manager Parameter Store

    Why it's wrong here

    AWS Systems Manager Parameter Store can store secrets as SecureString values encrypted with KMS, but it does not provide automatic rotation out of the box. You would need to build a custom rotation mechanism, often using AWS Lambda, which adds complexity and risk of inconsistent rotation. Parameter Store is better suited for configuration parameters, non-sensitive data, or secrets that can tolerate manual rotation, making it less robust than Secrets Manager for sensitive database credentials.

  • ✗

    Amazon DynamoDB

    Why it's wrong here

    Amazon DynamoDB is a fully managed NoSQL database designed for scalable, low-latency application data storage, not a secrets management service. Storing database credentials in DynamoDB forces you to implement your own encryption, access control, rotation, and audit logging, which is error-prone and lacks AWS-native lifecycle management. It is a poor choice for sensitive data because it does not offer built-in rotation or secret versioning, and integrating it with Lambda would require significant custom development.

  • ✗

    AWS IAM roles

    Why it's wrong here

    AWS IAM roles are an identity and access management construct that grants permissions to AWS principals, such as users, services, or Lambda functions, via temporary credentials. They do not store the secret values themselves; rather, they can enable IAM database authentication, which lets applications authenticate to supported AWS databases without retrieving a stored password. However, for the explicit purpose of storing sensitive data such as database credentials, IAM roles are not a storage service and cannot hold the secret content, making them an incorrect answer.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on DOP-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company requires that all secrets (e.g., database passwords) used by Lambda functions be rotated automatically every 30 days. Which combination of services should be used?

hard
  • A.AWS CloudHSM and AWS Lambda
  • ✓ B.AWS Secrets Manager and AWS Lambda
  • C.AWS Systems Manager Parameter Store and AWS Lambda
  • D.AWS KMS and AWS Lambda

Why B: AWS Secrets Manager is the correct choice because it natively supports automatic secret rotation on a configurable schedule (e.g., every 30 days) using a Lambda function as the rotation handler. Secrets Manager directly integrates with Lambda to invoke the rotation logic, updating the secret value and propagating the change to the target database or service without custom infrastructure. CloudHSM, Parameter Store, and KMS do not provide built-in, scheduled rotation of secrets with automatic Lambda invocation.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.