A company stores RDS database credentials in AWS Systems Manager Parameter Store as SecureString parameters. The security team requires that database passwords rotate automatically every 30 days. Which change should a solutions architect recommend?
AWS Secrets Manager is the only service in the options that natively integrates with Amazon RDS to rotate credentials with a managed Lambda rotation function, which you can configure to run every 30 days. The rotation process updates the database password, the secret value, and the secret's versions atomically and can be tested for rollback, eliminating the need for custom rotation code. Enabling rotation adds minimal operational overhead — you just choose the 30-day interval and the rotation Lambda provisions itself with the appropriate IAM role and permissions. This directly meets the requirement and is the recommended AWS pattern for automated RDS credential rotation.
Why this answer
AWS Secrets Manager provides native automatic rotation for RDS credentials using a managed Lambda function that rotates the secret on a defined schedule and updates the database password atomically.
Parameter Store SecureString does not support built-in automatic rotation — rotation must be implemented manually with custom automation. Secrets Manager is specifically designed for secrets requiring lifecycle management including rotation, auditing, and fine-grained access control.
Exam trap
Both services encrypt values using KMS, which causes candidates to treat them as equivalent. Only Secrets Manager provides automatic rotation with managed Lambda integration and rotation history. Parameter Store is appropriate for configuration values and static secrets.
Whenever automatic rotation is a security policy requirement, Secrets Manager is the answer.
Why the other options are wrong
Creating a custom EventBridge rule + Lambda for rotation works but requires development and maintenance effort. It lacks native rotation history and is more complex than the purpose-built Secrets Manager solution.
There is no built-in automatic rotation toggle in Parameter Store. This feature does not exist in the Parameter Store console — automatic rotation is a Secrets Manager capability.
AWS Config detects and alerts on compliance drift but cannot automatically rotate a database password. SNS notification is a detection mechanism, not a remediation mechanism.