Courseiva
Data Protection →hardMultiple Choice

SCS-C02 Data Protection Practice Question

A company uses AWS Secrets Manager to rotate secrets for its RDS database. The rotation fails periodically, and the security team needs to troubleshoot. Which CloudWatch metric should be monitored to detect rotation failures?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS/SecretsManager: SecretRotationSucceeded

The correct metric to monitor for Secrets Manager rotation failures is `AWS/SecretsManager:SecretRotationSucceeded`. When rotation fails, the `SecretRotationSucceeded` metric reports a value of 0, allowing the security team to set alarms. Option A is incorrect because KMS key usage metrics are not specific to rotation. Option C is incorrect because Lambda invocations may not capture all rotation failures and are not a direct indicator. Option D is incorrect because RDS metrics do not include Secrets Manager rotation status.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS/KMS: KeyUsage

    Why it's wrong here

    KeyUsage in the AWS/KMS namespace counts cryptographic operations performed with a customer master key, such as Encrypt, Decrypt, or GenerateDataKey. Secrets Manager uses a KMS key to encrypt the secret, but KMS does not expose a metric describing the rotation state or the scheduled rotation result. An increase or absence of KeyUsage therefore tells you nothing about whether a rotation succeeded or failed, only that the key may have been used. Monitoring this metric would not satisfy the requirement to detect rotation failures.

  • ✓

    AWS/SecretsManager: SecretRotationSucceeded

    Why this is correct

    The AWS/SecretsManager namespace provides SecretRotationSucceeded, which is published after each automatic rotation attempt for a secret and increments when the rotation callback completes successfully. The complementary SecretRotationFailed metric reports failures; by using an alarm on SecretRotationSucceeded with a period and statistic appropriate for the rotation schedule, you can detect missed or unsuccessful rotations. Because this metric is emitted by the Secrets Manager service directly from the rotation process, it is the most precise signal for verifying that rotation is working as configured. For example, you can alarm when SecretRotationSucceeded equals zero for the expected rotation interval.

  • ✗

    AWS/Lambda: Invocations

    Why it's wrong here

    Rotation in Secrets Manager is implemented through a Lambda function, but CloudWatch Invocations only reports the number of times that function is invoked. A rotation attempt might fail after the function has started—for example, due to a network timeout or an invalid master secret—while still counting as an invocation and causing retries. Additionally, Lambda retries failed invocations, so Invocations can exceed the number of rotation attempts and cannot distinguish successful rotations from failed ones. Thus, while it relates to rotation plumbing, it is not a reliable indicator of rotation health.

  • ✗

    AWS/RDS: DatabaseConnections

    Why it's wrong here

    DatabaseConnections measures the current number of sessions to an Amazon RDS instance and is published by the RDS service. This metric is influenced by application workload and connection pool settings, not by the Secrets Manager rotation lifecycle. A rotation can succeed or fail without ever changing the database connection count, and connections can remain established with old credentials, so this metric provides no visibility into whether the secret was rotated. It is therefore not an appropriate signal for monitoring Secrets Manager rotation errors.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.