SAA-C03 Design Secure Architectures Practice Question
A Lambda function for a claims portal needs to read a database password. The password must rotate automatically every 30 days and should not be stored in environment variables. Which service should be used?
⚠ Common exam trap
Candidates often confuse AWS Systems Manager Parameter Store SecureString with Secrets Manager, assuming Parameter Store can also handle automatic rotation, but Parameter Store lacks native rotation capabilities and requires custom automation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Secrets Manager with rotation enabled
AWS Secrets Manager is the correct choice because it is purpose-built for securely storing, automatically rotating, and managing secrets like database passwords. It supports automatic rotation every 30 days via a built-in Lambda rotation function, and it avoids storing the password in environment variables, which are visible in the Lambda console and logs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Systems Manager Parameter Store SecureString without automation
Why it's wrong here
AWS Systems Manager Parameter Store SecureString stores secrets encrypted with a KMS key, but it has no built-in mechanism for automatic rotation. You would have to write custom code to rotate the database password and update the parameter yourself, so it does not provide the managed lifecycle that meets the requirement.
- ✗
An encrypted object in Amazon S3
Why it's wrong here
Placing an encrypted object in Amazon S3 secures data at rest using SSE-KMS, but S3 is object storage rather than a purpose-built secret store. It lacks native APIs to retrieve the secret as a value, and you would have to manually version and overwrite the object every time the credential changes, making automatic rotation impossible.
- ✗
A KMS-encrypted Lambda environment variable
Why it's wrong here
A Lambda environment variable can be encrypted with KMS to protect it at rest, but the value is fixed at deployment time and cannot be rotated without redeploying the function. Environment variables are also visible in the Lambda configuration and are not designed for dynamic retrieval of database credentials, so this fails the rotation and security lifecycle requirement.
- ✓
AWS Secrets Manager with rotation enabled
Why this is correct
AWS Secrets Manager with rotation enabled stores the database credentials as a secret encrypted with a KMS key and automatically invokes a rotation Lambda function on a schedule to change the password. The Lambda can call GetSecretValue to fetch the current credentials, and the managed rotation eliminates manual credential updates, making it the right choice.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SAA-C03 question from scratch — 935 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.