DOP-C02 Security and Compliance Practice Question
A company uses AWS Secrets Manager to rotate secrets for an RDS database. The rotation Lambda function fails with a timeout error. Which configuration change is MOST likely to resolve the issue?
⚠ Common exam trap
Test-takers frequently confuse a timeout error with a connectivity error and incorrectly choose to place the Lambda in the same VPC, overlooking that the function must already be in the VPC to even attempt the rotation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Increase the Lambda function timeout.
The Lambda function is timing out during the secret rotation process, which involves connecting to the RDS database, generating a new password, and updating the secret. Increasing the Lambda function timeout directly addresses the symptom by allowing more time for the rotation to complete, especially if the database response is slow or the network latency is high. This is the most direct fix for a timeout error, as the default Lambda timeout (3 seconds) is often insufficient for database operations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Increase the Lambda function timeout.
Why this is correct
The Lambda rotation function must perform multiple sequential operations—connect to the RDS database, run an ALTER USER statement, and call UpdateSecret to store the new password—all of which can exceed the default 3-second timeout, especially during cold starts or slow network conditions. Increasing the function timeout directly prevents the execution from being terminated mid-rotation, allowing the full workflow to complete before Secrets Manager marks the step as failed. This is the correct fix because timeout errors indicate the function is being killed before finishing, not that it lacks compute resources or network access.
- ✗
Increase the Lambda function memory.
Why it's wrong here
Increasing Lambda memory allocates more CPU and improves execution speed, but it does not extend the maximum allowed execution time for the function. The timeout value is a separate configuration parameter that remains unchanged regardless of memory size, so a slow database query or API call can still exceed the limit and trigger the same timeout error. Memory tuning is for performance bottlenecks like CPU-bound code, not for situations where the function simply needs more wall-clock time to complete its operations.
- ✗
Place the Lambda function in the same VPC as the RDS instance.
Why it's wrong here
Placing the Lambda function in the same VPC as the RDS instance solves network reachability problems, such as missing route tables or security group rules, but it has no effect on the function's execution timeout. If the timeout error occurs after the function has successfully connected and is still processing, the VPC placement does not alter how long the invocation is allowed to run. This change only matters if the original failure was due to network connection timeouts, not when the function is already inside the rotation flow and exceeds the configured duration.
- ✗
Configure the Lambda function to retry on failure.
Why it's wrong here
Enabling retries makes the Lambda service invoke the function again after a timeout failure, but it does not reduce the time required for each attempt. Since every invocation will still hit the same 3-second cap and be terminated before finishing, each retry will produce the identical timeout error, and the overall rotation will continue to fail. Retry policies are useful for transient failures like temporary network glitches, not for deterministic timeouts caused by insufficient execution duration.
Visual reference
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on DOP-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company uses AWS Secrets Manager to rotate secrets for an RDS database. The rotation Lambda function fails with a timeout error. What is the most likely cause?
medium- A.The Lambda function's execution role lacks the required IAM permissions.
- ✓ B.The Lambda function is not configured to access the VPC where the RDS instance resides.
- C.The secret rotation schedule is set to less than 24 hours.
- D.The Lambda function does not have permission to access the S3 bucket.
Why B: The most likely cause of the timeout error is that the Lambda function is not configured to access the VPC where the RDS instance resides. When Secrets Manager rotates a secret for an RDS database, the rotation Lambda function must connect to the database to update the credentials. If the Lambda function is not attached to the same VPC (or a VPC with proper routing and security group rules), it cannot reach the RDS instance, causing network connection attempts to hang until the function times out.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.