Courseiva
Design Secure Architectures →mediumMultiple Choice

SAA-C03 Design Secure Architectures Practice Question

A team runs an application on Amazon EC2 that connects to an Aurora database. The database password must rotate automatically every 30 days, and the application should retrieve the current secret at runtime using an IAM role. Which AWS service is the best fit?

⚠ Common exam trap

It's easy for candidates to confuse AWS Systems Manager Parameter Store (which can store secrets but lacks native rotation) with Secrets Manager, or incorrectly assume KMS can store and rotate credentials because it handles encryption keys.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Secrets Manager with rotation enabled.

AWS Secrets Manager is the best fit because it natively supports automatic rotation of database credentials on a schedule (e.g., every 30 days) and integrates directly with Amazon RDS/Aurora to update the password. The application can retrieve the current secret at runtime using an IAM role attached to the EC2 instance, without hardcoding credentials. Secrets Manager also provides built-in secret rotation with Lambda, ensuring zero downtime during password changes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Systems Manager Parameter Store standard parameters.

    Why it's wrong here

    AWS Systems Manager Parameter Store standard parameters are designed for configuration values like AMI IDs, strings, or lists, and they support secure string parameters encrypted with KMS. However, standard parameters do not provide built-in automatic rotation; you would need to build and schedule a custom rotation Lambda function. In contrast, AWS Secrets Manager includes native rotation with a managed Lambda template for common databases, automatic credential generation, and lifecycle controls, so Parameter Store is not the intended service for this use case.

    When this WOULD be correct

    If the question required storing configuration data (e.g., database endpoint, port) without rotation, or if the application needed to retrieve parameters at runtime without automatic rotation, Parameter Store would be appropriate.

  • ✓

    AWS Secrets Manager with rotation enabled.

    Why this is correct

    Secrets Manager is designed for secure secret storage with built-in rotation support and fine-grained access through IAM. In this case, the application can retrieve the current database credentials at runtime with its EC2 role, while the secret is rotated on a schedule without embedding passwords in code. This reduces operational risk, improves auditability, and avoids manual password changes that often cause outages.

  • ✗

    AWS KMS, because KMS stores credentials and rotates them automatically.

    Why it's wrong here

    AWS KMS is a key management service that creates, stores, and rotates cryptographic keys used to encrypt data, not a secret store for application credentials. It does not store database passwords or expose them directly to applications; instead, it provides envelope encryption operations like Encrypt and Decrypt. While KMS can encrypt a secret file stored elsewhere, it lacks the ability to automatically generate new database credentials or integrate with database user management, making it inappropriate as a direct replacement for Secrets Manager.

    When this WOULD be correct

    A question asks which service should be used to encrypt data at rest for an application that stores sensitive files in Amazon S3, with requirements for automatic key rotation and centralized key management. AWS KMS would be the correct answer.

  • ✗

    Amazon S3 with server-side encryption and versioning.

    Why it's wrong here

    Amazon S3 is an object storage service, not a runtime secret store. While server-side encryption (SSE-S3 or SSE-KMS) protects data at rest and versioning preserves prior object states, S3 has no native mechanism to generate, rotate, or automatically expire database credentials. Using S3 would require your application to fetch a static credential object and handle rotation manually, and it lacks integration with IAM roles for fine-grained secret retrieval, making it operationally unsuitable for database password management.

    When this WOULD be correct

    An application needs to store and retrieve large configuration files (e.g., database connection strings) with versioning and encryption, but does not require automatic rotation or IAM-based access; S3 with SSE and versioning would be appropriate.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SAA-C03 exam frequently reuses these exact scenarios with slightly different constraints.

✓AWS Secrets Manager with rotation enabled.Correct answer▾

Why this is correct

Secrets Manager is designed for secure secret storage with built-in rotation support and fine-grained access through IAM. In this case, the application can retrieve the current database credentials at runtime with its EC2 role, while the secret is rotated on a schedule without embedding passwords in code. This reduces operational risk, improves auditability, and avoids manual password changes that often cause outages.

✗AWS Systems Manager Parameter Store standard parameters.Wrong answer — click to see why▾

Why this is wrong here

Systems Manager Parameter Store standard parameters do not support automatic rotation of secrets; they require manual updates or custom automation, whereas the question mandates automatic rotation every 30 days.

★ When this WOULD be the correct answer

If the question required storing configuration data (e.g., database endpoint, port) without rotation, or if the application needed to retrieve parameters at runtime without automatic rotation, Parameter Store would be appropriate.

Why candidates choose this

Candidates may confuse Parameter Store with Secrets Manager because both can store secrets securely, but they overlook that Parameter Store lacks built-in rotation capabilities.

✗AWS KMS, because KMS stores credentials and rotates them automatically.Wrong answer — click to see why▾

Why this is wrong here

AWS KMS is a key management service for encryption keys, not a service for storing or rotating database passwords. It does not provide automatic rotation of secrets or direct retrieval by applications via IAM roles.

★ When this WOULD be the correct answer

A question asks which service should be used to encrypt data at rest for an application that stores sensitive files in Amazon S3, with requirements for automatic key rotation and centralized key management. AWS KMS would be the correct answer.

Why candidates choose this

Candidates may confuse KMS's key rotation capability with secret rotation, or mistakenly think KMS can store credentials because it manages encryption keys that protect secrets.

✗Amazon S3 with server-side encryption and versioning.Wrong answer — click to see why▾

Why this is wrong here

Amazon S3 with server-side encryption and versioning does not provide automatic password rotation or native integration with IAM roles for runtime secret retrieval; it is designed for object storage, not dynamic secrets management.

★ When this WOULD be the correct answer

An application needs to store and retrieve large configuration files (e.g., database connection strings) with versioning and encryption, but does not require automatic rotation or IAM-based access; S3 with SSE and versioning would be appropriate.

Why candidates choose this

Candidates may think S3 can store any data securely and versioning provides a form of rotation, overlooking that Secrets Manager is purpose-built for managing secrets with rotation and IAM integration.

Analysis generated from the official SAA-C03blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.