SAA-C03 Design Secure Architectures Practice Question
A Lambda function for a IoT ingestion API needs to read a database password. The password must rotate automatically every 30 days and should not be stored in environment variables. Which service should be used?
⚠ Common exam trap
A common mix-up: candidates confuse AWS Systems Manager Parameter Store SecureString with Secrets Manager, but Parameter Store lacks native automatic rotation, making it unsuitable for the 30-day rotation requirement without additional custom automation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Secrets Manager with rotation enabled
AWS Secrets Manager is the correct choice because it is purpose-built for securely storing, automatically rotating, and managing secrets such as database passwords. With rotation enabled, Secrets Manager can automatically rotate the password every 30 days without requiring custom code, and it integrates natively with Lambda via the AWS SDK to retrieve the secret at runtime, avoiding storage in environment variables.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS Secrets Manager with rotation enabled
Why this is correct
AWS Secrets Manager is purpose-built for storing and retrieving secrets at runtime, and the rotation-enabled configuration automatically rotates database credentials on a schedule using an accompanying AWS Lambda function. This ensures the Lambda function always reads a valid, current secret without manual intervention, and access can be scoped via IAM policies. It also integrates with CloudTrail for auditing secret access, making it the appropriate choice for a production IoT ingestion pipeline.
- ✗
A KMS-encrypted Lambda environment variable
Why it's wrong here
Encrypting a Lambda environment variable with a KMS key protects the secret at rest and in transit, but the plaintext value is still embedded in the function configuration and can be retrieved by anyone with `lambda:GetFunctionConfiguration` or `lambda:GetEnvironmentVariables` permissions. Since the value is static, there is no automatic rotation; when the credential changes you must redeploy the function or manually update the configuration, and the old secret remains visible in configuration history. This approach is therefore operationally brittle and does not satisfy a secret lifecycle management requirement.
- ✗
AWS Systems Manager Parameter Store SecureString without automation
Why it's wrong here
AWS Systems Manager Parameter Store's SecureString parameter is encrypted with a KMS key, but this service does not automatically rotate the secret value; rotation requires you to build a separate automation or Lambda function to update the parameter on a schedule. Parameter Store also lacks native integration with database services for automatic user/credential rotation, so the secret can become stale. While Parameter Store is a valid secret store, 'without automation' fails the need for managed, scheduled rotation that Secrets Manager provides.
- ✗
An encrypted object in Amazon S3
Why it's wrong here
An encrypted object in Amazon S3 uses SSE-KMS to protect data at rest, but S3 is just an object store—it has no concept of secret generation, rotation, or lifecycle management for credentials. To rotate a secret stored this way, you would have to upload a new object, then update every consuming Lambda function's reference to the new object key or rely on bucket versioning, which still requires external orchestration. Additionally, IAM permission management for object access is coarser than Secrets Manager's resource-based policies, and there is no audit trail tied to secret retrieval.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.