Courseiva
Security and Compliance →mediumMultiple Choice

DOP-C02 Security and Compliance Practice Question

A company uses AWS Secrets Manager to store database credentials. The security team requires that secrets be automatically rotated every 30 days. Which rotation strategy should the engineer configure to meet this requirement with minimal operational overhead?

⚠ Common exam trap

DOP-C02 often tests the trade-off between pre-built and custom rotation — candidates may over-engineer by choosing a custom Lambda when the pre-built function already supports the database type with minimal overhead.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable automatic rotation using the pre-built Lambda rotation function for the database type.

AWS Secrets Manager supports automatic rotation using pre-built Lambda rotation functions tailored to specific database types (e.g., Amazon RDS MySQL, PostgreSQL, Aurora). Enabling this built-in rotation with a 30-day schedule meets the requirement with minimal operational overhead because AWS manages the Lambda function, rotation logic, and secret update. This is the standard, lowest-effort approach for database credential rotation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Manually rotate the secret every 30 days using the AWS CLI.

    Why it's wrong here

    Manual rotation via the AWS CLI is not a scheduled, automated process—it depends on a human remembering to run the rotation every 30 days, and it does not use Secrets Manager's built-in rotation machinery. While you could change the database password and update the secret with `aws secretsmanager update-secret`, the approach is error-prone, lacks automatic coordination between the database and the secret, and leaves the credential static in the interim. This fails to meet the goal of eliminating secrets exposure risk and fails to leverage Secrets Manager's native rotation lifecycle.

  • ✗

    Store the secret in AWS Systems Manager Parameter Store with a SecureString parameter.

    Why it's wrong here

    AWS Systems Manager Parameter Store SecureString can store a secret, but it offers no native, managed rotation capability—there is no built-in Lambda integration or scheduling to rotate the database password automatically. You would need to build an independent automation flow to generate a new password, update the database, and synchronize the parameter, which recreates the exact operational burden you are trying to avoid. Additionally, Parameter Store secure parameters are not tightly integrated with AWS Secrets Manager's rotation stages or the ability to coordinate credential changes with services like Amazon RDS.

  • ✓

    Enable automatic rotation using the pre-built Lambda rotation function for the database type.

    Why this is correct

    Secrets Manager's pre-built Lambda rotation function (e.g., for Amazon RDS MySQL, PostgreSQL, Oracle, or SQL Server) is the correct choice because it provides a fully managed, automated rotation pattern that requires minimal configuration. When you enable rotation, Secrets Manager executes the Lambda on a configurable schedule (e.g., every 30 days), and the function updates the database password and the stored secret atomically using the Secrets Manager rotation sequence (createSecret, setSecret, testSecret, finishSecret). This ensures the secret and the database remain in sync with no temporary breakage and no custom code to write or maintain.

  • ✗

    Enable automatic rotation with a custom Lambda function.

    Why it's wrong here

    A custom Lambda function for rotation is technically possible but is the wrong choice here because AWS already provides a well-tested, optional pre-built rotation template that covers the database type. Building a custom function forces you to implement and maintain the full rotation lifecycle (including all four rotation steps, error handling, logging, IAM permissions, and VPC networking) when you could simply select the template and configure the schedule. This adds unnecessary complexity, introduces potential security and availability risks from code bugs, and does not provide any advantage over the native pre-built solution.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on DOP-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company uses AWS Secrets Manager to store database credentials. The security team needs to automatically rotate the secrets every 30 days. Which action should be taken?

easy
  • ✓ A.Enable automatic rotation on the secret and configure the rotation interval to 30 days
  • B.Manually rotate the secret every 30 days using the AWS Management Console
  • C.Store the secret in AWS Systems Manager Parameter Store and use a scheduled Lambda to update it
  • D.Use AWS KMS to rotate the secret by re-encrypting with a new key

Why A: AWS Secrets Manager supports automatic rotation of secrets using a Lambda rotation function. By enabling automatic rotation and setting the rotation interval to 30 days, the secret is rotated automatically without manual intervention. This meets the security team's requirement for automatic rotation every 30 days.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.