SCS-C02 Management and Security Governance Practice Question
A company has a requirement to automatically rotate secrets for an RDS database every 90 days. The secrets are stored in AWS Secrets Manager. Which resource should be configured to perform the rotation?
⚠ Common exam trap
SCS-C02 often tests the misconception that EventBridge or other services directly rotate secrets, when in fact Secrets Manager relies on a Lambda function to perform the rotation logic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Lambda function
AWS Secrets Manager uses a Lambda function to perform the actual rotation of secrets. When you configure rotation for a secret, you specify a Lambda function that implements the rotation logic, including creating a new secret version, updating the database credentials, and testing the new credentials. The Lambda function is invoked by Secrets Manager on the schedule you define (e.g., every 90 days). Thus, the resource that performs the rotation is the Lambda function.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
CloudWatch Logs subscription filter
Why it's wrong here
CloudWatch Logs subscription filter enables real-time streaming of log events to destinations like Lambda or Kinesis for monitoring, alerting, or analytics. It operates entirely on log data that already exists in a log group; it has no visibility into AWS Secrets Manager secret lifecycle events, nor can it set or update secret values. Its purpose is to process logs, not to orchestrate or execute a state-changing operation such as secret rotation. Thus it is not a relevant mechanism for meeting the rotation requirement.
- ✗
Amazon EventBridge scheduled rule
Why it's wrong here
Amazon EventBridge scheduled rule can act as a trigger to invoke a Lambda function on a schedule, but it does not contain any logic to rotate secrets itself. The actual rotation workflow—generating a new secret value, updating the secret in AWS Secrets Manager, and applying it to the target service—runs inside a Lambda function. EventBridge only provides the timing event; it cannot read, write, or modify secret material, nor does it interact with the target database or application. Therefore, it cannot satisfy an automatic rotation requirement on its own.
- ✗
AWS Config rule
Why it's wrong here
An AWS Config rule is a compliance evaluation engine that continuously checks whether your AWS resources, such as secrets, meet defined policies—for example, whether rotation is enabled. It can detect non-compliant secrets and optionally trigger a remediation action through SSM Automation or a Lambda function, but it does not perform the rotation itself. Config rules are read-only assessors; they produce compliance results and cannot directly generate or update secret material. Therefore, while it can monitor rotation, it cannot be mistaken for the actual rotation executor.
- ✓
AWS Lambda function
Why this is correct
AWS Secrets Manager uses a Lambda function as the compute engine for its native rotation feature. When rotation is triggered, Secrets Manager invokes the Lambda function with different stages (createSecret, setSecret, testSecret, finishSecret) to generate and store a new secret value and update the associated service or database. You must provide the Lambda function with an IAM role that has permissions to access the secret and the target resource, and for private resources, it must be attached to a VPC. This is why the correct answer is the Lambda function, not a scheduling or compliance service.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.