SAA-C03 Practice Question: AWS Secrets Manager provides native automatic…
A company stores RDS database credentials in AWS Systems Manager Parameter Store as SecureString parameters. The security team requires that database passwords rotate automatically every 30 days. Which change should a solutions architect recommend?
⚠ Common exam trap
Both services encrypt values using KMS, which causes candidates to treat them as equivalent. Only Secrets Manager provides automatic rotation with managed Lambda integration and rotation history. Parameter Store is appropriate for configuration values and static secrets. Whenever automatic rotation is a security policy requirement, Secrets Manager is the answer.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Migrate the credentials to AWS Secrets Manager and enable automatic rotation with a 30-day schedule
AWS Secrets Manager provides native automatic rotation for RDS credentials using a managed Lambda function that rotates the secret on a defined schedule and updates the database password atomically. Parameter Store SecureString does not support built-in automatic rotation — rotation must be implemented manually with custom automation. Secrets Manager is specifically designed for secrets requiring lifecycle management including rotation, auditing, and fine-grained access control.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a scheduled EventBridge rule to invoke a Lambda function that updates the Parameter Store SecureString value every 30 days
Why it's wrong here
This approach is functionally plausible but requires you to write and maintain a custom Lambda function that authenticates to RDS, generates a new password, updates the SecureString, and updates the database — plus handle retries, versioning, and rollback on failure. Parameter Store SecureString values do not have native rotation, so you also lose the built-in rotation history, secret version tracking, and automated integration that Secrets Manager provides for RDS. An EventBridge schedule invokes Lambda on a cron-triggered basis, but this is a hand-rolled solution with no resource-level permission management for the secret. It fails the goal of using a managed service to minimize operational overhead.
- ✓
Migrate the credentials to AWS Secrets Manager and enable automatic rotation with a 30-day schedule
Why this is correct
AWS Secrets Manager is the only service in the options that natively integrates with Amazon RDS to rotate credentials with a managed Lambda rotation function, which you can configure to run every 30 days. The rotation process updates the database password, the secret value, and the secret's versions atomically and can be tested for rollback, eliminating the need for custom rotation code. Enabling rotation adds minimal operational overhead — you just choose the 30-day interval and the rotation Lambda provisions itself with the appropriate IAM role and permissions. This directly meets the requirement and is the recommended AWS pattern for automated RDS credential rotation.
- ✗
Enable Parameter Store SecureString automatic rotation in the AWS console
Why it's wrong here
Parameter Store SecureString does not have a built-in automatic rotation feature at all — there is no console toggle or configuration to rotate a SecureString on a schedule. You can store encrypted strings in Parameter Store, but rotating them requires you to create an external trigger (e.g., a scheduled Lambda) that rewrites the value, and that custom code is exactly what Secrets Manager's native rotation eliminates. The console only supports creating, updating, and deleting parameters; it does not provide a rotation lifecycle. Therefore selecting this option is based on a false premise, and it cannot satisfy the requirement without significant additional implementation.
- ✗
Configure AWS Config to detect password age and trigger an SNS notification after 30 days
Why it's wrong here
AWS Config is a governance and compliance service that evaluates resource configurations against rules; it has no mechanism to generate or update RDS credentials. A Config rule can flag that the password exceeds the 30-day age and send an SNS alert, but the alert only notifies an operator — someone still has to manually rotate the password, which fails the requirement for automated rotation. Even if you paired Config with a custom remediation action via Systems Manager Automation, that would require building bespoke logic, not a native capability. Secrets Manager's rotation does this natively, so this option is operationally incomplete.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
One of 935 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.