Courseiva
Design Secure Architectures →mediumMultiple Choice

SAA-C03 Design Secure Architectures Practice Question

A fintech company runs a containerized payment API on Amazon ECS with AWS Fargate. The security team requires that the API access a stored database credential without hardcoding it in the task definition or environment variables. The credential must be encrypted at rest and automatically rotated every 90 days. The API also needs to retrieve the credential at container startup with minimal latency. Which solution meets these requirements?

⚠ Common exam trap

The trap here is assuming Parameter Store SecureString provides automatic rotation, when rotation must be custom-built with Lambda and EventBridge.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Store the credential in AWS Secrets Manager, enable automatic rotation, and grant the ECS task role permission to call secretsmanager:GetSecretValue.

AWS Secrets Manager is designed for storing, encrypting, and automatically rotating secrets such as database credentials. By using the ECS task role to call GetSecretValue, the container retrieves the credential at startup without embedding it in the task definition. Native rotation every 90 days satisfies the compliance requirement, and KMS encryption at rest plus IAM policies enforce least privilege.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Store the credential in an encrypted Amazon S3 object and grant the ECS task role s3:GetObject. Configure a Lambda function to rotate the credential every 90 days.

    Why it's wrong here

    Storing a credential in an S3 object requires custom encryption handling and a custom rotation Lambda, which increases operational overhead and risk of misconfiguration. S3 does not natively rotate database credentials, and the container would need to fetch and parse the object. This approach is less secure and more complex than using a purpose-built secrets service with native rotation.

  • ✗

    Store the credential in AWS Systems Manager Parameter Store as a SecureString, and grant the ECS task role ssm:GetParameter. Enable automatic rotation through Parameter Store.

    Why it's wrong here

    Parameter Store SecureString encrypts values at rest, but it does not provide native automatic rotation for database credentials. Rotation must be implemented manually with a Lambda function and EventBridge schedule. The requirement for automatic rotation every 90 days is not met out of the box, making this option insufficient despite its encryption capability.

  • ✗

    Store the credential in an encrypted Amazon EBS volume attached to the Fargate task, and grant the task role permission to mount the volume.

    Why it's wrong here

    AWS Fargate tasks cannot attach Amazon EBS volumes directly; Fargate uses ephemeral storage or Amazon EFS. Even if EBS were supported, it does not provide credential rotation or fine-grained IAM access to the secret itself. This option fails both the architectural constraint and the rotation requirement, making it unsuitable for the scenario.

  • ✓

    Store the credential in AWS Secrets Manager, enable automatic rotation, and grant the ECS task role permission to call secretsmanager:GetSecretValue.

    Why this is correct

    AWS Secrets Manager supports native automatic rotation for supported databases and can rotate credentials every 90 days. The ECS task role can be granted least-privilege access to GetSecretValue, and the container retrieves the secret at startup. Secrets Manager encrypts secrets at rest using KMS and integrates with IAM, satisfying the encryption and access-control requirements without hardcoding credentials.

About these practice questions

Courseiva writes every SAA-C03 question from scratch — 935 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.