Courseiva

SAA-C03 Design Secure Architectures Practice Question

A financial services company runs a three-tier web application on AWS. The application servers in a private subnet must retrieve database credentials from AWS Secrets Manager at startup. The security team requires that the credentials never be stored on disk and that access be granted only to the specific IAM role attached to the instances. Which solution meets these requirements with the LEAST operational overhead?

⚠ Common exam trap

The trap here is treating Parameter Store SecureString as equivalent to Secrets Manager, ignoring that native automatic rotation for database credentials is a Secrets Manager feature.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Retrieve the secret from AWS Secrets Manager using the AWS SDK with the instance's IAM role, and configure automatic rotation for the secret.

AWS Secrets Manager is purpose-built for storing and rotating database credentials. Using the instance's IAM role to call GetSecretValue keeps credentials in memory, avoids disk storage, and supports least privilege through IAM policies scoped to the specific secret. Automatic rotation removes manual effort. The other options either require custom rotation logic, expose secrets in less secure locations, or add unnecessary components.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Retrieve the secret from AWS Secrets Manager using the AWS SDK with the instance's IAM role, and configure automatic rotation for the secret.

    Why this is correct

    Secrets Manager integrates natively with IAM roles, so the application can call GetSecretValue using temporary credentials from the instance profile without storing anything on disk. Built-in rotation for supported databases updates the secret and the database password automatically, minimizing operational effort. IAM policies can restrict access to the specific secret and role, satisfying least privilege. This is the intended AWS pattern for this scenario.

  • ✗

    Use AWS Systems Manager Parameter Store SecureString parameters and retrieve them with the AWS CLI during instance bootstrap.

    Why it's wrong here

    Parameter Store SecureString can store secrets, but it lacks native automatic rotation for database credentials. The team would need to build and maintain rotation workflows, increasing operational overhead. The requirement emphasizes least operational overhead, and Secrets Manager provides built-in rotation for supported databases, making Parameter Store a poorer fit despite being a valid secure storage option.

  • ✗

    Embed the credentials in the AWS Lambda environment variables and have the application servers retrieve them through an API Gateway endpoint.

    Why it's wrong here

    Environment variables are visible to anyone with Lambda configuration read access and are not designed for secret storage or rotation. Adding API Gateway introduces an unnecessary public or private endpoint, authentication layer, and latency. This approach increases both security risk and operational complexity while failing to provide managed rotation, so it does not meet the requirements.

  • ✗

    Store the credentials in an encrypted Amazon S3 object and have the application download and decrypt them at startup using the instance role.

    Why it's wrong here

    Downloading credentials from S3 and decrypting them with KMS requires custom code, key management, and rotation logic. It also risks writing the credentials to disk or logs during processing. Secrets Manager already provides managed rotation, auditing, and fine-grained IAM integration, so this approach adds unnecessary operational overhead and does not meet the requirement as cleanly.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.