DOP-C02 Security and Compliance Practice Question
A company uses AWS Secrets Manager to store database credentials. The security team requires that secrets be automatically rotated every 30 days. Which rotation strategy should the engineer configure to meet this requirement with minimal operational overhead?
⚠ Common exam trap
DOP-C02 often tests the trade-off between pre-built and custom rotation — candidates may over-engineer by choosing a custom Lambda when the pre-built function already supports the database type with minimal overhead.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable automatic rotation using the pre-built Lambda rotation function for the database type.
AWS Secrets Manager supports automatic rotation using pre-built Lambda rotation functions tailored to specific database types (e.g., Amazon RDS MySQL, PostgreSQL, Aurora). Enabling this built-in rotation with a 30-day schedule meets the requirement with minimal operational overhead because AWS manages the Lambda function, rotation logic, and secret update. This is the standard, lowest-effort approach for database credential rotation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Manually rotate the secret every 30 days using the AWS CLI.
Why it's wrong here
Manual rotation via the AWS CLI is not a scheduled, automated process—it depends on a human remembering to run the rotation every 30 days, and it does not use Secrets Manager's built-in rotation machinery. While you could change the database password and update the secret with `aws secretsmanager update-secret`, the approach is error-prone, lacks automatic coordination between the database and the secret, and leaves the credential static in the interim. This fails to meet the goal of eliminating secrets exposure risk and fails to leverage Secrets Manager's native rotation lifecycle.
- ✗
Store the secret in AWS Systems Manager Parameter Store with a SecureString parameter.
Why it's wrong here
AWS Systems Manager Parameter Store SecureString can store a secret, but it offers no native, managed rotation capability—there is no built-in Lambda integration or scheduling to rotate the database password automatically. You would need to build an independent automation flow to generate a new password, update the database, and synchronize the parameter, which recreates the exact operational burden you are trying to avoid. Additionally, Parameter Store secure parameters are not tightly integrated with AWS Secrets Manager's rotation stages or the ability to coordinate credential changes with services like Amazon RDS.
- ✓
Enable automatic rotation using the pre-built Lambda rotation function for the database type.
Why this is correct
Secrets Manager's pre-built Lambda rotation function (e.g., for Amazon RDS MySQL, PostgreSQL, Oracle, or SQL Server) is the correct choice because it provides a fully managed, automated rotation pattern that requires minimal configuration. When you enable rotation, Secrets Manager executes the Lambda on a configurable schedule (e.g., every 30 days), and the function updates the database password and the stored secret atomically using the Secrets Manager rotation sequence (createSecret, setSecret, testSecret, finishSecret). This ensures the secret and the database remain in sync with no temporary breakage and no custom code to write or maintain.
- ✗
Enable automatic rotation with a custom Lambda function.
Why it's wrong here
A custom Lambda function for rotation is technically possible but is the wrong choice here because AWS already provides a well-tested, optional pre-built rotation template that covers the database type. Building a custom function forces you to implement and maintain the full rotation lifecycle (including all four rotation steps, error handling, logging, IAM permissions, and VPC networking) when you could simply select the template and configure the schedule. This adds unnecessary complexity, introduces potential security and availability risks from code bugs, and does not provide any advantage over the native pre-built solution.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on DOP-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company uses AWS Secrets Manager to store database credentials. The security team needs to automatically rotate the secrets every 30 days. Which action should be taken?
easy- ✓ A.Enable automatic rotation on the secret and configure the rotation interval to 30 days
- B.Manually rotate the secret every 30 days using the AWS Management Console
- C.Store the secret in AWS Systems Manager Parameter Store and use a scheduled Lambda to update it
- D.Use AWS KMS to rotate the secret by re-encrypting with a new key
Why A: AWS Secrets Manager supports automatic rotation of secrets using a Lambda rotation function. By enabling automatic rotation and setting the rotation interval to 30 days, the secret is rotated automatically without manual intervention. This meets the security team's requirement for automatic rotation every 30 days.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.