SCS-C02 Data Protection Practice Question
A company uses AWS Secrets Manager to store database credentials. The security team needs to ensure that secrets are automatically rotated every 30 days. The rotation function must be implemented with minimal operational overhead. Which approach should be used?
⚠ Common exam trap
SCS-C02 often tests the misconception that you must build custom Lambda/EventBridge automation for rotation, when Secrets Manager's native rotation feature already handles scheduling and versioning.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable automatic rotation in Secrets Manager and configure the rotation interval to 30 days
AWS Secrets Manager has native, built-in rotation support that requires only enabling rotation and specifying a rotation interval and a Lambda rotation function (AWS provides templates for RDS, Redshift, DocumentDB, etc.). Setting the interval to 30 days satisfies the requirement with the least operational overhead because Secrets Manager manages the schedule, invokes the Lambda, and updates the secret version automatically.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create an Amazon EventBridge rule that triggers a Lambda function to rotate the secret
Why it's wrong here
Creating an EventBridge rule to invoke a Lambda rotation function manually replicates Secrets Manager's built-in rotation scheduler. Secrets Manager already natively handles rotation timing, invokes the Lambda function with the appropriate secret ARN and token, and manages the secret's version staging labels. Adding EventBridge introduces an extra component that must be configured, monitored, and secured, increasing operational overhead without any functional benefit.
- ✗
Use AWS CLI to schedule a cron job that runs every 30 days and rotates the secret
Why it's wrong here
Scheduling an AWS CLI command from a cron job requires an external compute environment, such as an EC2 instance, which must stay running and hold AWS CLI credentials. You would have to write custom logic to generate a new password, update the database, and then store the secret using the CLI, all while handling retries and failures manually. Unlike Secrets Manager's managed rotation, this approach lacks versioning, staging labels, and the built-in coordination with the database, making it fragile and high-overhead.
- ✗
Use Amazon CloudWatch Events to invoke an AWS Lambda function that updates the secret
Why it's wrong here
Using CloudWatch Events to trigger a Lambda that simply updates the secret value bypasses the core of rotation: creating a new secret version and only marking it AWSCURRENT after the database has accepted the new credentials. A direct update overwrites the secret and can cause downtime if the database is not updated first, and you lose the AWSPREVIOUS version needed for rollback. Secrets Manager's rotation function template handles this safely via staging labels and secure invocation, whereas a custom EventBridge-triggered update does not.
- ✓
Enable automatic rotation in Secrets Manager and configure the rotation interval to 30 days
Why this is correct
Enabling automatic rotation in Secrets Manager with a 30-day interval is the correct managed solution. Secrets Manager schedules the rotation, invokes the configured Lambda rotation function, and coordinates the change of the database password with the secret's version lifecycle using AWSCURRENT and AWSPREVIOUS staging labels. You simply choose the rotation interval, and the service handles all scheduling, retries, and permissions, providing the lowest operational overhead. This also works with common database services like RDS via the built-in rotation templates.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.