SCS-C02 Data Protection Practice Question
A company uses AWS Secrets Manager to rotate secrets for its RDS database. The rotation fails periodically, and the security team needs to troubleshoot. Which CloudWatch metric should be monitored to detect rotation failures?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS/SecretsManager: SecretRotationSucceeded
The correct metric to monitor for Secrets Manager rotation failures is `AWS/SecretsManager:SecretRotationSucceeded`. When rotation fails, the `SecretRotationSucceeded` metric reports a value of 0, allowing the security team to set alarms. Option A is incorrect because KMS key usage metrics are not specific to rotation. Option C is incorrect because Lambda invocations may not capture all rotation failures and are not a direct indicator. Option D is incorrect because RDS metrics do not include Secrets Manager rotation status.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS/KMS: KeyUsage
Why it's wrong here
KeyUsage in the AWS/KMS namespace counts cryptographic operations performed with a customer master key, such as Encrypt, Decrypt, or GenerateDataKey. Secrets Manager uses a KMS key to encrypt the secret, but KMS does not expose a metric describing the rotation state or the scheduled rotation result. An increase or absence of KeyUsage therefore tells you nothing about whether a rotation succeeded or failed, only that the key may have been used. Monitoring this metric would not satisfy the requirement to detect rotation failures.
- ✓
AWS/SecretsManager: SecretRotationSucceeded
Why this is correct
The AWS/SecretsManager namespace provides SecretRotationSucceeded, which is published after each automatic rotation attempt for a secret and increments when the rotation callback completes successfully. The complementary SecretRotationFailed metric reports failures; by using an alarm on SecretRotationSucceeded with a period and statistic appropriate for the rotation schedule, you can detect missed or unsuccessful rotations. Because this metric is emitted by the Secrets Manager service directly from the rotation process, it is the most precise signal for verifying that rotation is working as configured. For example, you can alarm when SecretRotationSucceeded equals zero for the expected rotation interval.
- ✗
AWS/Lambda: Invocations
Why it's wrong here
Rotation in Secrets Manager is implemented through a Lambda function, but CloudWatch Invocations only reports the number of times that function is invoked. A rotation attempt might fail after the function has started—for example, due to a network timeout or an invalid master secret—while still counting as an invocation and causing retries. Additionally, Lambda retries failed invocations, so Invocations can exceed the number of rotation attempts and cannot distinguish successful rotations from failed ones. Thus, while it relates to rotation plumbing, it is not a reliable indicator of rotation health.
- ✗
AWS/RDS: DatabaseConnections
Why it's wrong here
DatabaseConnections measures the current number of sessions to an Amazon RDS instance and is published by the RDS service. This metric is influenced by application workload and connection pool settings, not by the Secrets Manager rotation lifecycle. A rotation can succeed or fail without ever changing the database connection count, and connections can remain established with old credentials, so this metric provides no visibility into whether the secret was rotated. It is therefore not an appropriate signal for monitoring Secrets Manager rotation errors.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.