Courseiva
Design Secure Architectures →mediumMultiple Choice

SAA-C03 Design Secure Architectures Practice Question

A Lambda function for a healthcare document service needs to read a database password. The password must rotate automatically every 30 days and should not be stored in environment variables. Which service should be used?

⚠ Common exam trap

Many candidates confuse Systems Manager Parameter Store (which can store SecureStrings) with Secrets Manager, but Parameter Store lacks automatic rotation, making it unsuitable for a 30-day rotation requirement without additional custom automation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Secrets Manager with rotation enabled

AWS Secrets Manager is the correct choice because it is designed specifically for storing and automatically rotating database credentials. It supports native rotation for Amazon RDS, Redshift, and DocumentDB with a built-in Lambda rotation function, and it can rotate secrets on a schedule (e.g., every 30 days) without storing the password in environment variables. This meets the healthcare document service's requirement for automatic rotation and secure storage.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A KMS-encrypted Lambda environment variable

    Why it's wrong here

    Encrypting a Lambda environment variable with a KMS customer master key protects the secret at rest and in transit to the function, but it does not provide any lifecycle management. The encrypted value is a static configuration item; if the secret rotates, you must manually update the environment variable and redeploy the Lambda function. This option fails the core requirement because there is no automated rotation mechanism built into Lambda environment variables.

  • ✗

    An encrypted object in Amazon S3

    Why it's wrong here

    Storing an encrypted object in Amazon S3—whether using SSE-KMS or client-side encryption—secures the data bytes but treats the secret as a flat file with no rotation semantics. S3 does not natively track secret versions for credentials or invoke rotation functions; you would have to build a custom process to replace the object and then update every consumer. Since the question explicitly requires rotation, an S3 object is merely a storage location, not a secret lifecycle service.

  • ✗

    AWS Systems Manager Parameter Store SecureString without automation

    Why it's wrong here

    AWS Systems Manager Parameter Store SecureString does encrypt parameter values with KMS and supports versioning, but without automation it has no built-in secret rotation. You would need to implement your own rotation trigger (e.g., EventBridge rules, Step Functions, or a custom Lambda) and manually update the parameter each time the secret changes. While Parameter Store is a valid secret store, the absence of managed rotation makes it an incomplete solution for the stated requirement.

  • ✓

    AWS Secrets Manager with rotation enabled

    Why this is correct

    AWS Secrets Manager is purpose-built for storing secrets and, when rotation is enabled, it automatically rotates the secret value on a schedule using an associated Lambda function. It also keeps previous versions during rotation so applications can continue to work while the new secret is being tested, and it integrates natively with services like RDS, Redshift, and DocumentDB. This directly satisfies the need for automated secret rotation and eliminates the operational overhead of manually updating credentials.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 935 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.