Courseiva
Security and Compliance →easyMultiple Choice

DOP-C02 Security and Compliance Practice Question

A company uses AWS Secrets Manager to store database credentials. The security team wants to automatically rotate secrets every 30 days. The database is an Amazon RDS for PostgreSQL instance. The team has configured automatic rotation with a Lambda function that updates the password in RDS and Secrets Manager. However, after the first rotation, the application starts getting database connection errors. The application uses a connection string with the secret ARN and retrieves the secret from Secrets Manager at startup using the AWS SDK. Which of the following is the most likely cause of the connection errors?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The application caches the secret at startup and does not refresh it after rotation.

If the application caches the secret at startup, it will not retrieve the updated password after rotation, causing connection errors. Option A is incorrect because a Lambda timeout or throttling would prevent the rotation from completing, but the rotation succeeded (new password set), so the issue is on the application side. Option C is incorrect because if the Lambda lacked permissions to update the secret, the rotation would have failed entirely, not just after the first rotation. Option D is incorrect because Amazon RDS does not have built-in automatic password rotation; Secrets Manager manages the rotation, so there is no conflict.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The Lambda function is not configured with a sufficient timeout and is being throttled.

    Why it's wrong here

    Lambda timeout or throttling would prevent the rotation function from completing, leaving the old password valid in RDS, so the application would still connect. It tempts because throttling genuinely breaks rotation, but the symptom here is errors after a successful first rotation, not a stalled one.

  • ✓

    The application caches the secret at startup and does not refresh it after rotation.

    Why this is correct

    The application reads the secret once at startup and holds it in memory, so after rotation the cached credentials no longer match the new RDS password, producing authentication failures. Refreshing the secret from Secrets Manager on each connection, or handling rotation-aware retrieval, resolves the connection errors.

  • ✗

    The Lambda function does not have permission to update the secret in Secrets Manager.

    Why it's wrong here

    Missing Lambda permission would fail the rotation itself, leaving the old password valid, so the application would still connect. It is tempting because IAM permissions are a common rotation fault, and would be correct if rotation errored rather than succeeded.

  • ✗

    The RDS instance has automatic password rotation enabled, which conflicts with Secrets Manager rotation.

    Why it's wrong here

    RDS for PostgreSQL has no separate automatic password rotation feature, so nothing conflicts with Secrets Manager; the real fault lies in the rotation Lambda or cached connections. It tempts because RDS does manage master credentials in some engines, but that mechanism is unrelated to Secrets Manager's rotation schedule.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.