SAA-C03 Design Secure Architectures Practice Question
A mobile banking backend uses Amazon RDS for PostgreSQL. Application credentials must not be stored on the EC2 instances, and authentication should use short-lived credentials. What should the architect recommend? The design must avoid adding custom operational scripts.
⚠ Common exam trap
A common mix-up: candidates confuse network-level controls (security groups) with authentication mechanisms, or assume that storing credentials in user data or AMIs is acceptable because they are 'hidden' from the OS, when in fact they are still long-lived and accessible via metadata or AMI inspection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
IAM database authentication for RDS with an EC2 instance role
IAM database authentication for RDS allows EC2 instances to authenticate to PostgreSQL using a short-lived token generated via the IAM instance profile, eliminating the need to store credentials on the instance. The token is obtained by calling the RDS generate_db_auth_token API with the instance's IAM role, and it is valid for 15 minutes by default. This approach satisfies the requirement for short-lived credentials and avoids custom operational scripts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Store the database password in user data
Why it's wrong here
Storing the database password in user data is insecure because user data is available to any process running on the instance via the instance metadata service at http://169.254.169.254/latest/user-data. It is also returned in the EC2 console and API responses unless explicitly redacted, making it visible to anyone with read access. A plaintext secret in user data has no rotation mechanism, and if the instance is compromised, the attacker can trivially retrieve the password and reuse it against the RDS database.
- ✓
IAM database authentication for RDS with an EC2 instance role
Why this is correct
IAM database authentication for RDS with an EC2 instance role is the correct approach because it lets the application generate a short-lived (15-minute) authentication token using SigV4, eliminating any stored database password. The EC2 instance assumes an instance role with rds-db:connect permissions, and the application presents the token to PostgreSQL over SSL; RDS validates the token against IAM rather than a static password. This provides centralized credential management via IAM roles, automatic rotation of credentials, and ensures no secret is baked into configurations, user data, or code.
- ✗
Use a security group rule that allows only application instances
Why it's wrong here
Using a security group rule to allow only application instances restricts network access to the RDS endpoint, but it is purely a network-layer control and does not authenticate the identity of the caller. Any process on an allowed instance can still attempt SQL login, and if the instance is compromised, the attacker inherits the allowed network path; the database would still require a static password to be stored somewhere, reintroducing the original secret-management problem. Security groups complement authentication but cannot replace IAM database authentication or a robust password mechanism.
- ✗
Embed the database password in the AMI
Why it's wrong here
Embedding the database password in the AMI bakes a long-lived secret into a reusable image artifact that is copied, versioned, and launched in multiple environments. Anyone with access to the AMI—or any snapshot derived from it—can extract the password, and unauthorized AMI sharing can leak the secret outside your account. Rotating the password would require rebuilding and redeploying the AMI, which is slow, error-prone, and leaves old instances still holding stale credentials; the secret also remains recoverable from the AMI even after you stop using it.
Go deeper
Related to this question
About these practice questions
One of 935 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.