SAA-C03 Design Secure Architectures Practice Question
A financial services company runs a three-tier web application on AWS. The application servers in a private subnet must retrieve database credentials from AWS Secrets Manager at startup. The security team requires that the credentials never be stored on disk and that access be granted only to the specific IAM role attached to the instances. Which solution meets these requirements with the LEAST operational overhead?
⚠ Common exam trap
The trap here is treating Parameter Store SecureString as equivalent to Secrets Manager, ignoring that native automatic rotation for database credentials is a Secrets Manager feature.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Retrieve the secret from AWS Secrets Manager using the AWS SDK with the instance's IAM role, and configure automatic rotation for the secret.
AWS Secrets Manager is purpose-built for storing and rotating database credentials. Using the instance's IAM role to call GetSecretValue keeps credentials in memory, avoids disk storage, and supports least privilege through IAM policies scoped to the specific secret. Automatic rotation removes manual effort. The other options either require custom rotation logic, expose secrets in less secure locations, or add unnecessary components.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Retrieve the secret from AWS Secrets Manager using the AWS SDK with the instance's IAM role, and configure automatic rotation for the secret.
Why this is correct
Secrets Manager integrates natively with IAM roles, so the application can call GetSecretValue using temporary credentials from the instance profile without storing anything on disk. Built-in rotation for supported databases updates the secret and the database password automatically, minimizing operational effort. IAM policies can restrict access to the specific secret and role, satisfying least privilege. This is the intended AWS pattern for this scenario.
- ✗
Use AWS Systems Manager Parameter Store SecureString parameters and retrieve them with the AWS CLI during instance bootstrap.
Why it's wrong here
Parameter Store SecureString can store secrets, but it lacks native automatic rotation for database credentials. The team would need to build and maintain rotation workflows, increasing operational overhead. The requirement emphasizes least operational overhead, and Secrets Manager provides built-in rotation for supported databases, making Parameter Store a poorer fit despite being a valid secure storage option.
- ✗
Embed the credentials in the AWS Lambda environment variables and have the application servers retrieve them through an API Gateway endpoint.
Why it's wrong here
Environment variables are visible to anyone with Lambda configuration read access and are not designed for secret storage or rotation. Adding API Gateway introduces an unnecessary public or private endpoint, authentication layer, and latency. This approach increases both security risk and operational complexity while failing to provide managed rotation, so it does not meet the requirements.
- ✗
Store the credentials in an encrypted Amazon S3 object and have the application download and decrypt them at startup using the instance role.
Why it's wrong here
Downloading credentials from S3 and decrypting them with KMS requires custom code, key management, and rotation logic. It also risks writing the credentials to disk or logs during processing. Secrets Manager already provides managed rotation, auditing, and fine-grained IAM integration, so this approach adds unnecessary operational overhead and does not meet the requirement as cleanly.
Visual reference
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.