Courseiva
Data Protection →hardMultiple Choice

SCS-C02 Data Protection Practice Question

A company uses AWS Secrets Manager to store database credentials. The security team needs to ensure that secrets are automatically rotated every 30 days. The rotation function must be implemented with minimal operational overhead. Which approach should be used?

⚠ Common exam trap

SCS-C02 often tests the misconception that you must build custom Lambda/EventBridge automation for rotation, when Secrets Manager's native rotation feature already handles scheduling and versioning.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable automatic rotation in Secrets Manager and configure the rotation interval to 30 days

AWS Secrets Manager has native, built-in rotation support that requires only enabling rotation and specifying a rotation interval and a Lambda rotation function (AWS provides templates for RDS, Redshift, DocumentDB, etc.). Setting the interval to 30 days satisfies the requirement with the least operational overhead because Secrets Manager manages the schedule, invokes the Lambda, and updates the secret version automatically.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create an Amazon EventBridge rule that triggers a Lambda function to rotate the secret

    Why it's wrong here

    Creating an EventBridge rule to invoke a Lambda rotation function manually replicates Secrets Manager's built-in rotation scheduler. Secrets Manager already natively handles rotation timing, invokes the Lambda function with the appropriate secret ARN and token, and manages the secret's version staging labels. Adding EventBridge introduces an extra component that must be configured, monitored, and secured, increasing operational overhead without any functional benefit.

  • ✗

    Use AWS CLI to schedule a cron job that runs every 30 days and rotates the secret

    Why it's wrong here

    Scheduling an AWS CLI command from a cron job requires an external compute environment, such as an EC2 instance, which must stay running and hold AWS CLI credentials. You would have to write custom logic to generate a new password, update the database, and then store the secret using the CLI, all while handling retries and failures manually. Unlike Secrets Manager's managed rotation, this approach lacks versioning, staging labels, and the built-in coordination with the database, making it fragile and high-overhead.

  • ✗

    Use Amazon CloudWatch Events to invoke an AWS Lambda function that updates the secret

    Why it's wrong here

    Using CloudWatch Events to trigger a Lambda that simply updates the secret value bypasses the core of rotation: creating a new secret version and only marking it AWSCURRENT after the database has accepted the new credentials. A direct update overwrites the secret and can cause downtime if the database is not updated first, and you lose the AWSPREVIOUS version needed for rollback. Secrets Manager's rotation function template handles this safely via staging labels and secure invocation, whereas a custom EventBridge-triggered update does not.

  • ✓

    Enable automatic rotation in Secrets Manager and configure the rotation interval to 30 days

    Why this is correct

    Enabling automatic rotation in Secrets Manager with a 30-day interval is the correct managed solution. Secrets Manager schedules the rotation, invokes the configured Lambda rotation function, and coordinates the change of the database password with the secret's version lifecycle using AWSCURRENT and AWSPREVIOUS staging labels. You simply choose the rotation interval, and the service handles all scheduling, retries, and permissions, providing the lowest operational overhead. This also works with common database services like RDS via the built-in rotation templates.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.