Courseiva
Design for New Solutions →mediumMultiple Select

SAP-C02 Design for New Solutions Practice Question

A company is designing a new serverless application using AWS Lambda. The application needs to access an Amazon RDS for PostgreSQL database. The database credentials must be rotated automatically every 30 days. Which THREE steps should the company take to securely manage the credentials? (Choose three.)

⚠ Common exam trap

It's easy for candidates to confuse IAM roles for database access (which is only supported for Amazon RDS with IAM database authentication, not for standard PostgreSQL credentials) with the need to retrieve secrets via IAM permissions, leading them to select Option C instead of Option E.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Store the database credentials in AWS Secrets Manager.

Option A is correct because AWS Secrets Manager is the managed service designed to store and protect database credentials, and it natively supports Amazon RDS for PostgreSQL as a rotation target. Option B is correct because Secrets Manager provides built-in automatic rotation, and configuring rotation with a 30-day schedule satisfies the requirement to rotate credentials every 30 days without custom code. Option E is correct because the Lambda function must have an IAM role policy granting secretsmanager:GetSecretValue (and typically DescribeSecret) on the specific secret so it can retrieve the current credentials at runtime. Option C is not correct because granting the Lambda execution role direct access to RDS does not manage or rotate credentials, and database authentication still requires valid credentials. Option D is not correct because Secrets Manager already supplies rotation logic for RDS for PostgreSQL, so writing custom rotation logic in the application Lambda function is unnecessary and not a secure credential-management step.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Store the database credentials in AWS Secrets Manager.

    Why this is correct

    Secrets Manager is purpose-built for storing and retrieving database credentials securely, satisfying the 30-day rotation requirement natively. Unlike Lambda environment variables or Parameter Store, it integrates rotation scheduling and encryption, so credentials never reside in code or configuration files.

  • ✓

    Configure automatic rotation for the secret in AWS Secrets Manager.

    Why this is correct

    Configuring automatic rotation directly satisfies the mandatory 30-day rotation constraint. Secrets Manager invokes a Lambda rotation function that updates both the secret and the RDS PostgreSQL user password, eliminating manual intervention and ensuring credentials expire on schedule.

  • ✗

    Grant the Lambda function's IAM role permission to access the RDS database directly.

    Why it's wrong here

    Granting the Lambda role direct RDS access bypasses Secrets Manager, so credentials would be embedded or fetched manually and never rotated every 30 days. It is tempting because IAM database authentication removes passwords entirely, which would be correct for RDS engines that support it and where rotation is not mandated.

  • ✗

    Write custom rotation logic in the Lambda function to change the database password.

    Why it's wrong here

    Custom rotation logic inside the application Lambda duplicates what Secrets Manager's rotation Lambda already provides, and it cannot update the stored secret atomically. It is tempting because a Lambda can run SQL against PostgreSQL, which would be correct for bespoke credential stores outside Secrets Manager.

  • ✓

    Grant the Lambda function's IAM role permission to retrieve the secret from Secrets Manager.

    Why this is correct

    The Lambda execution role must hold secretsmanager:GetSecretValue permission, otherwise retrieval calls fail with AccessDenied. This grants least-privilege read access to the specific secret, enabling runtime credential fetching without embedding static credentials in code or environment variables.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

Courseiva writes every SAP-C02 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.