A company wants to securely store database credentials used by an application running on Amazon EC2. The credentials should be automatically rotated every 90 days. Which AWS service should be used?
AWS Secrets Manager is purpose-built for storing secrets like database credentials and natively supports automatic rotation through an integrated Lambda rotation function. It manages secret versions with AWSCURRENT and AWSPREVIOUS labels, allowing applications to reliably fetch rotated credentials without downtime. It also provides fine-grained access via IAM and resource policies, making it the correct service when the requirement is both secure storage and automatic rotation of database credentials.
Why this answer
AWS Secrets Manager is designed to securely store and manage secrets such as database credentials, and it provides built-in automatic rotation every 90 days (or custom intervals) using Lambda functions. It integrates natively with Amazon RDS, Redshift, and DocumentDB for rotation. IAM and KMS do not store secrets, and Parameter Store does not offer automatic rotation natively.
Exam trap
The trap is confusing Parameter Store with Secrets Manager; candidates may think Parameter Store can rotate secrets automatically, but it does not—rotation is a key differentiator of Secrets Manager.
How to eliminate wrong answers
Option A is wrong because AWS IAM is for identity and access management, not for storing database credentials. Option B is wrong because AWS KMS is a key management service for encryption keys, not for storing secrets. Option C is wrong because AWS Systems Manager Parameter Store can store secrets, but it does not provide automatic rotation; rotation must be implemented manually or via custom automation.