Courseiva

SAA-C03 Design Secure Architectures Practice Question

A company has a critical application running on Amazon EC2 instances that must access an Amazon RDS for MySQL database. The security team requires that the database credentials are never stored on the EC2 instances and that access to the database is auditable. The database is in a private subnet and only accepts connections from the application's security group. The company wants to implement a solution that automatically rotates the database password every 90 days. Which solution meets these requirements?

⚠ Common exam trap

The trap here is assuming that IAM database authentication can satisfy a requirement for rotating a database password, when in fact it eliminates passwords entirely and requires application code changes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Store the database credentials in AWS Secrets Manager with automatic rotation enabled. Configure the EC2 instance role to allow secretsmanager:GetSecretValue, and have the application retrieve the secret at runtime.

AWS Secrets Manager is the managed service designed for storing and rotating database credentials. It provides automatic rotation for Amazon RDS for MySQL, integrates with IAM for access control, and logs access via CloudTrail. The EC2 instances retrieve the secret at runtime, so credentials are never stored locally. This meets the no-hardcoded-credentials, automatic rotation, and auditability requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Store the database credentials in AWS Systems Manager Parameter Store as a SecureString parameter. Use a custom Lambda function to rotate the password every 90 days and update the parameter.

    Why it's wrong here

    Parameter Store SecureString encrypts the value, but it does not provide built-in automatic rotation for RDS credentials. You would need to build and maintain a custom Lambda function to rotate the password and update the parameter, which increases operational overhead and complexity. The requirement for automatic rotation every 90 days is not natively supported.

  • ✓

    Store the database credentials in AWS Secrets Manager with automatic rotation enabled. Configure the EC2 instance role to allow secretsmanager:GetSecretValue, and have the application retrieve the secret at runtime.

    Why this is correct

    AWS Secrets Manager stores the credentials securely and supports automatic rotation for Amazon RDS for MySQL. The EC2 instance role grants permission to retrieve the secret, so credentials are never stored on the instances. Access to the secret can be audited using AWS CloudTrail. This meets all requirements: no hardcoded credentials, automatic rotation, and auditability.

  • ✗

    Use IAM database authentication for Amazon RDS for MySQL. Configure the EC2 instance role with rds-db:connect permission, and have the application generate an authentication token.

    Why it's wrong here

    IAM database authentication eliminates the need for a static password, but it requires application code changes to generate an authentication token using the AWS SDK. The scenario does not state that application code can be modified. Additionally, IAM authentication does not support automatic password rotation because there is no password; however, the requirement explicitly mentions rotating the database password every 90 days, which implies a password-based approach.

  • ✗

    Store the database credentials in an encrypted Amazon S3 bucket. Use an AWS Lambda function triggered by Amazon EventBridge to rotate the password every 90 days and update the S3 object.

    Why it's wrong here

    Storing credentials in S3, even encrypted, is not a best practice for database secrets. It requires custom code for rotation and retrieval, and does not provide native integration with RDS for rotation. The solution lacks the auditability and managed rotation features of Secrets Manager. It also increases the risk of misconfiguration and unauthorized access.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.