Courseiva
Data Protection →easyMultiple Choice

SCS-C02 Data Protection Practice Question

A company needs to securely store database credentials that are used by an application running on Amazon EC2. The credentials must be automatically rotated every 90 days. Which AWS service should be used?

⚠ Common exam trap

SCS-C02 often tests the difference between Secrets Manager and Parameter Store, leading candidates to choose Parameter Store for automatic rotation when it lacks native rotation capabilities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Secrets Manager

AWS Secrets Manager is purpose-built for storing, retrieving, and automatically rotating database credentials. It natively supports rotation for Amazon RDS, Aurora, and other databases via Lambda rotation functions, and can rotate credentials every 90 days as required. This directly meets the requirement for secure storage and automatic rotation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS KMS

    Why it's wrong here

    AWS KMS is a managed service that creates and controls customer master keys (CMKs) used for encrypting and decrypting data, not for storing secrets like database passwords. While KMS can encrypt a secret that lives elsewhere, it provides no native mechanism to store the credential itself, manage versions, or automatically rotate database passwords. Therefore, KMS alone cannot satisfy the requirement of securely storing and rotating database credentials.

  • ✓

    AWS Secrets Manager

    Why this is correct

    AWS Secrets Manager is a purpose-built service for storing and managing database credentials, API keys, and other sensitive values. It natively supports automatic rotation of secrets using a customizable AWS Lambda function, with one-click integration for Amazon RDS, Redshift, and DocumentDB to rotate the password on the datastore as well. Because it combines secure storage, fine-grained IAM access control, secret versioning, and scheduled rotation, it directly meets the stated requirement for securely storing database credentials with automatic rotation.

  • ✗

    AWS IAM roles for EC2

    Why it's wrong here

    IAM roles for EC2 provide temporary AWS credentials to instances through an instance profile, enabling the instance to call AWS APIs without embedding long-lived keys. They do not store or manage database passwords; database authentication username/password pairs are application-level secrets that must be delivered separately from the instance's AWS API credentials. Although Amazon RDS can use IAM database authentication instead of a password, that mechanism still doesn't involve storing the database password in a managed secret store, so IAM roles are the wrong service for this requirement.

  • ✗

    AWS Systems Manager Parameter Store

    Why it's wrong here

    AWS Systems Manager Parameter Store can hold secrets as SecureString parameters, but it does not provide native automatic rotation of those secrets. To rotate a database password stored in Parameter Store, you must build and schedule custom automation (for example, Lambda plus EventBridge) to update both the parameter and the database, whereas Secrets Manager performs this rotation out of the box. Since the company's primary need is a securely stored database credential that rotates automatically, Parameter Store is not the best fit despite its lower cost.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.