SAP-C02 Design for New Solutions Practice Question
A company is migrating a legacy three-tier application to AWS. The application servers run on Amazon EC2 instances behind an Application Load Balancer, and the database is a self-managed MySQL instance on an EC2 instance. The company requires that database credentials never be stored in application code or configuration files, and that credentials be automatically rotated every 30 days without application restarts. Which solution meets these requirements with the LEAST operational overhead?
⚠ Common exam trap
The trap here is assuming that AWS Systems Manager Parameter Store provides automatic rotation for database credentials, when it only stores parameters and requires a custom rotation solution.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Store the database credentials in AWS Secrets Manager and configure automatic rotation. Grant the EC2 instance role permission to retrieve the secret, and update the application to fetch credentials from Secrets Manager at startup and on connection failure.
AWS Secrets Manager is designed to securely store and automatically rotate database credentials for supported databases, including self-managed MySQL on EC2, using a Lambda rotation function. It integrates with IAM roles, eliminating hardcoded credentials, and allows applications to retrieve credentials on demand, so rotation occurs without application restarts. This meets the requirements with minimal operational effort.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Store the credentials in AWS Systems Manager Parameter Store as SecureString parameters. Use an AWS Lambda function triggered by Amazon EventBridge to rotate the credentials every 30 days, and update the application to read the parameters at startup.
Why it's wrong here
Parameter Store SecureString encrypts values, but it does not provide native automatic rotation for database credentials. You would need to build and maintain a custom rotation Lambda and manage the rotation schedule, which adds operational overhead. The requirement for automatic rotation without application restarts is not met out of the box.
- ✗
Use AWS Identity and Access Management (IAM) database authentication for MySQL. Configure the application to generate an authentication token using the EC2 instance role, and connect to the database using that token.
Why it's wrong here
IAM database authentication is only available for Amazon RDS for MySQL and Aurora, not for a self-managed MySQL instance on EC2. This solution cannot be implemented as described. Additionally, it would not automatically rotate credentials every 30 days; tokens are short-lived but the underlying IAM authentication setup is not applicable here.
- ✗
Store the credentials in an encrypted Amazon S3 bucket. Use an EC2 user data script to download and decrypt the credentials at instance launch, and rotate them manually every 30 days by updating the S3 object and restarting the application servers.
Why it's wrong here
This approach stores credentials in S3 and requires manual rotation, violating the automatic rotation requirement. It also requires application restarts to pick up new credentials, which is explicitly disallowed. The operational overhead of manual rotation and restarts is high, and there is no native integration with database rotation.
- ✓
Store the database credentials in AWS Secrets Manager and configure automatic rotation. Grant the EC2 instance role permission to retrieve the secret, and update the application to fetch credentials from Secrets Manager at startup and on connection failure.
Why this is correct
AWS Secrets Manager natively supports automatic rotation for supported databases, including self-managed MySQL on EC2, using a Lambda rotation function. It integrates with IAM roles for EC2, so no static credentials are stored in code or configuration. The application can retrieve credentials via the Secrets Manager API when needed, enabling rotation without restarts.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
One of 984 original SAP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.