SAA-C03 Design Secure Architectures Practice Question
A team runs an application on Amazon EC2 that connects to an Aurora database. The database password must rotate automatically every 30 days, and the application should retrieve the current secret at runtime using an IAM role. Which AWS service is the best fit?
⚠ Common exam trap
It's easy for candidates to confuse AWS Systems Manager Parameter Store (which can store secrets but lacks native rotation) with Secrets Manager, or incorrectly assume KMS can store and rotate credentials because it handles encryption keys.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Secrets Manager with rotation enabled.
AWS Secrets Manager is the best fit because it natively supports automatic rotation of database credentials on a schedule (e.g., every 30 days) and integrates directly with Amazon RDS/Aurora to update the password. The application can retrieve the current secret at runtime using an IAM role attached to the EC2 instance, without hardcoding credentials. Secrets Manager also provides built-in secret rotation with Lambda, ensuring zero downtime during password changes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Systems Manager Parameter Store standard parameters.
Why it's wrong here
AWS Systems Manager Parameter Store standard parameters are designed for configuration values like AMI IDs, strings, or lists, and they support secure string parameters encrypted with KMS. However, standard parameters do not provide built-in automatic rotation; you would need to build and schedule a custom rotation Lambda function. In contrast, AWS Secrets Manager includes native rotation with a managed Lambda template for common databases, automatic credential generation, and lifecycle controls, so Parameter Store is not the intended service for this use case.
When this WOULD be correct
If the question required storing configuration data (e.g., database endpoint, port) without rotation, or if the application needed to retrieve parameters at runtime without automatic rotation, Parameter Store would be appropriate.
- ✓
AWS Secrets Manager with rotation enabled.
Why this is correct
Secrets Manager is designed for secure secret storage with built-in rotation support and fine-grained access through IAM. In this case, the application can retrieve the current database credentials at runtime with its EC2 role, while the secret is rotated on a schedule without embedding passwords in code. This reduces operational risk, improves auditability, and avoids manual password changes that often cause outages.
- ✗
AWS KMS, because KMS stores credentials and rotates them automatically.
Why it's wrong here
AWS KMS is a key management service that creates, stores, and rotates cryptographic keys used to encrypt data, not a secret store for application credentials. It does not store database passwords or expose them directly to applications; instead, it provides envelope encryption operations like Encrypt and Decrypt. While KMS can encrypt a secret file stored elsewhere, it lacks the ability to automatically generate new database credentials or integrate with database user management, making it inappropriate as a direct replacement for Secrets Manager.
When this WOULD be correct
A question asks which service should be used to encrypt data at rest for an application that stores sensitive files in Amazon S3, with requirements for automatic key rotation and centralized key management. AWS KMS would be the correct answer.
- ✗
Amazon S3 with server-side encryption and versioning.
Why it's wrong here
Amazon S3 is an object storage service, not a runtime secret store. While server-side encryption (SSE-S3 or SSE-KMS) protects data at rest and versioning preserves prior object states, S3 has no native mechanism to generate, rotate, or automatically expire database credentials. Using S3 would require your application to fetch a static credential object and handle rotation manually, and it lacks integration with IAM roles for fine-grained secret retrieval, making it operationally unsuitable for database password management.
When this WOULD be correct
An application needs to store and retrieve large configuration files (e.g., database connection strings) with versioning and encryption, but does not require automatic rotation or IAM-based access; S3 with SSE and versioning would be appropriate.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SAA-C03 exam frequently reuses these exact scenarios with slightly different constraints.
✓AWS Secrets Manager with rotation enabled.Correct answer▾
Why this is correct
Secrets Manager is designed for secure secret storage with built-in rotation support and fine-grained access through IAM. In this case, the application can retrieve the current database credentials at runtime with its EC2 role, while the secret is rotated on a schedule without embedding passwords in code. This reduces operational risk, improves auditability, and avoids manual password changes that often cause outages.
✗AWS Systems Manager Parameter Store standard parameters.Wrong answer — click to see why▾
Why this is wrong here
Systems Manager Parameter Store standard parameters do not support automatic rotation of secrets; they require manual updates or custom automation, whereas the question mandates automatic rotation every 30 days.
★ When this WOULD be the correct answer
If the question required storing configuration data (e.g., database endpoint, port) without rotation, or if the application needed to retrieve parameters at runtime without automatic rotation, Parameter Store would be appropriate.
Why candidates choose this
Candidates may confuse Parameter Store with Secrets Manager because both can store secrets securely, but they overlook that Parameter Store lacks built-in rotation capabilities.
✗AWS KMS, because KMS stores credentials and rotates them automatically.Wrong answer — click to see why▾
Why this is wrong here
AWS KMS is a key management service for encryption keys, not a service for storing or rotating database passwords. It does not provide automatic rotation of secrets or direct retrieval by applications via IAM roles.
★ When this WOULD be the correct answer
A question asks which service should be used to encrypt data at rest for an application that stores sensitive files in Amazon S3, with requirements for automatic key rotation and centralized key management. AWS KMS would be the correct answer.
Why candidates choose this
Candidates may confuse KMS's key rotation capability with secret rotation, or mistakenly think KMS can store credentials because it manages encryption keys that protect secrets.
✗Amazon S3 with server-side encryption and versioning.Wrong answer — click to see why▾
Why this is wrong here
Amazon S3 with server-side encryption and versioning does not provide automatic password rotation or native integration with IAM roles for runtime secret retrieval; it is designed for object storage, not dynamic secrets management.
★ When this WOULD be the correct answer
An application needs to store and retrieve large configuration files (e.g., database connection strings) with versioning and encryption, but does not require automatic rotation or IAM-based access; S3 with SSE and versioning would be appropriate.
Why candidates choose this
Candidates may think S3 can store any data securely and versioning provides a form of rotation, overlooking that Secrets Manager is purpose-built for managing secrets with rotation and IAM integration.
Analysis generated from the official SAA-C03blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.