SCS-C02 Alternating Users Rotation Practice Question
A company uses AWS Secrets Manager to rotate database credentials automatically. The security team wants to ensure that while the secret is being rotated, applications can always retrieve a valid credential. Which rotation strategy should be used?
⚠ Common exam trap
Candidates may mistakenly believe that single user rotation (Option B) is acceptable, but it causes a temporary gap in valid credentials. The alternating users strategy avoids this gap.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the alternating users rotation strategy.
The alternating users rotation strategy (Option D) is correct because it creates two sets of credentials—one active and one pending—so that during rotation, at least one set remains valid for applications. Option A (IAM database authentication) is not a rotation strategy for Secrets Manager. Option B (single user rotation with immediate update) would cause a brief period where the credential is invalid, leading to potential downtime. Option C (disabling automatic rotation) defeats the purpose of automated rotation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use AWS IAM database authentication instead.
Why it's wrong here
IAM database authentication is an access-control alternative that uses short-lived tokens, not a Secrets Manager rotation strategy, and Secrets Manager cannot 'rotate' database passwords when IAM auth is used. Enabling IAM auth requires the database engine to support it (for example, Amazon Aurora MySQL/PostgreSQL or RDS MySQL/PostgreSQL) and changes how applications authenticate, rather than keeping the database user's password rotated in the secret. It therefore does not meet the stated requirement of using Secrets Manager to rotate database credentials while maintaining continuous access.
- ✗
Use a single user rotation with immediate update.
Why it's wrong here
In a single user rotation with immediate update, the rotation function changes the password for the one database user in place, which means the AWSCURRENT secret value is invalid for a short period between the database password change and the secret update completion. Applications already holding the old credential get rejected, and applications fetching AWSCURRENT before it is updated may still receive the stale value or fail. This approach works only if clients have retries and can tolerate brief connection failures, which is precisely what the company wants to avoid.
- ✗
Disable automatic rotation and manually update credentials.
Why it's wrong here
Manually updating credentials removes Secrets Manager's rotation mechanism entirely, leaving the secret version stale until an operator remembers to change it. This approach increases operational burden and security risk, and it still requires coordinating application restart/reconnect without a guaranteed overlap of valid credentials. It does not address the requirement for continuous availability during a credential change; it only trades automation for a manual, error-prone process.
- ✓
Use the alternating users rotation strategy.
Why this is correct
The alternating users rotation strategy creates a second set of database credentials while the original remains valid, then promotes the new credentials to AWSCURRENT and demotes the old ones to AWSPREVIOUS. Applications can continue using either credential during the transition, so there is no window where no valid password exists. This makes it the right choice when a database cannot tolerate even brief downtime during Secrets Manager rotation.
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.