SAA-C03 Design Secure Architectures Practice Question
A company hosts a web application on Amazon EC2 instances in a VPC. The application must access an Amazon RDS for MySQL database. The security team requires that database credentials never be stored in application code or on disk, and that credentials be automatically rotated every 30 days. Which solution should a solutions architect implement?
⚠ Common exam trap
The trap here is assuming that Parameter Store SecureString parameters rotate automatically like Secrets Manager secrets, when Parameter Store requires custom rotation logic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Store the credentials in AWS Secrets Manager and configure automatic rotation using the provided RDS rotation Lambda function.
AWS Secrets Manager provides managed storage and native rotation for RDS credentials. The application retrieves the secret at runtime, so no credentials are embedded in code or persisted on disk. The built-in rotation Lambda handles the 30-day schedule automatically, meeting both the security and operational requirements without custom code.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Store the credentials in an encrypted Amazon S3 object and have the application download and decrypt it at startup.
Why it's wrong here
Storing credentials in S3, even encrypted, requires the application to fetch and cache them, and there is no native rotation. The credentials could end up in memory or logs, and rotation would need custom automation. This does not meet the requirement that credentials never be stored on disk or in code.
- ✓
Store the credentials in AWS Secrets Manager and configure automatic rotation using the provided RDS rotation Lambda function.
Why this is correct
Secrets Manager is designed for this use case: it stores secrets encrypted with KMS, and it offers built-in rotation for Amazon RDS through a managed Lambda function. The application retrieves credentials at runtime via the API or SDK, so nothing is stored in code or on disk, and rotation occurs automatically on the configured schedule.
- ✗
Store the credentials in AWS Systems Manager Parameter Store as a SecureString parameter and enable automatic rotation with a custom Lambda function.
Why it's wrong here
Parameter Store SecureString parameters are encrypted with KMS, but native automatic rotation for RDS credentials is not provided. A custom Lambda rotation function would be required, adding operational overhead, whereas the requirement calls for a managed rotation mechanism. This makes it less suitable than a purpose-built secret management service.
- ✗
Use IAM database authentication for RDS and eliminate the need for a database password entirely.
Why it's wrong here
IAM database authentication can replace static passwords, but it requires application code changes to generate authentication tokens and does not provide a 30-day rotation of a stored secret. The scenario specifically requires rotating credentials, so this approach does not satisfy the stated requirement.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SAA-C03 question from scratch — 935 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.