Courseiva

SCS-C02 Management and Security Governance Practice Question

A company has a requirement to automatically rotate secrets for an RDS database every 90 days. The secrets are stored in AWS Secrets Manager. Which resource should be configured to perform the rotation?

⚠ Common exam trap

SCS-C02 often tests the misconception that EventBridge or other services directly rotate secrets, when in fact Secrets Manager relies on a Lambda function to perform the rotation logic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Lambda function

AWS Secrets Manager uses a Lambda function to perform the actual rotation of secrets. When you configure rotation for a secret, you specify a Lambda function that implements the rotation logic, including creating a new secret version, updating the database credentials, and testing the new credentials. The Lambda function is invoked by Secrets Manager on the schedule you define (e.g., every 90 days). Thus, the resource that performs the rotation is the Lambda function.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    CloudWatch Logs subscription filter

    Why it's wrong here

    CloudWatch Logs subscription filter enables real-time streaming of log events to destinations like Lambda or Kinesis for monitoring, alerting, or analytics. It operates entirely on log data that already exists in a log group; it has no visibility into AWS Secrets Manager secret lifecycle events, nor can it set or update secret values. Its purpose is to process logs, not to orchestrate or execute a state-changing operation such as secret rotation. Thus it is not a relevant mechanism for meeting the rotation requirement.

  • ✗

    Amazon EventBridge scheduled rule

    Why it's wrong here

    Amazon EventBridge scheduled rule can act as a trigger to invoke a Lambda function on a schedule, but it does not contain any logic to rotate secrets itself. The actual rotation workflow—generating a new secret value, updating the secret in AWS Secrets Manager, and applying it to the target service—runs inside a Lambda function. EventBridge only provides the timing event; it cannot read, write, or modify secret material, nor does it interact with the target database or application. Therefore, it cannot satisfy an automatic rotation requirement on its own.

  • ✗

    AWS Config rule

    Why it's wrong here

    An AWS Config rule is a compliance evaluation engine that continuously checks whether your AWS resources, such as secrets, meet defined policies—for example, whether rotation is enabled. It can detect non-compliant secrets and optionally trigger a remediation action through SSM Automation or a Lambda function, but it does not perform the rotation itself. Config rules are read-only assessors; they produce compliance results and cannot directly generate or update secret material. Therefore, while it can monitor rotation, it cannot be mistaken for the actual rotation executor.

  • ✓

    AWS Lambda function

    Why this is correct

    AWS Secrets Manager uses a Lambda function as the compute engine for its native rotation feature. When rotation is triggered, Secrets Manager invokes the Lambda function with different stages (createSecret, setSecret, testSecret, finishSecret) to generate and store a new secret value and update the associated service or database. You must provide the Lambda function with an IAM role that has permissions to access the secret and the target resource, and for private resources, it must be attached to a VPC. This is why the correct answer is the Lambda function, not a scheduling or compliance service.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.