SCS-C02 Data Protection Practice Question
A company uses AWS Secrets Manager to store database credentials for an application running on EC2 instances. The security engineer needs to ensure that the credentials are automatically rotated every 30 days and that the application can retrieve the credentials without hardcoding them. The engineer has configured a rotation Lambda function and enabled rotation. However, the application is still using hardcoded credentials. What should the engineer do to ensure the application retrieves credentials dynamically?
⚠ Common exam trap
The trap here is thinking that enabling rotation in Secrets Manager automatically updates the application's credentials, but the application must be coded to fetch the secret dynamically.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Modify the application code to call the Secrets Manager GetSecretValue API using the AWS SDK, and grant the EC2 instance role permission to access the secret.
The application must be modified to use the Secrets Manager API to retrieve credentials at runtime. This ensures that the application always gets the current credentials after rotation. The EC2 instance role must have permissions to call GetSecretValue on the secret. This is the standard pattern for dynamic secret retrieval.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use AWS AppConfig to deploy the credentials to the EC2 instances and configure the application to read from a local file.
Why it's wrong here
AWS AppConfig is designed for application configuration, not for secure secret storage and rotation. Storing database credentials in AppConfig and writing them to a local file would not provide the security and automatic rotation features of Secrets Manager. This method could expose credentials and does not meet the requirement for automatic rotation.
- ✓
Modify the application code to call the Secrets Manager GetSecretValue API using the AWS SDK, and grant the EC2 instance role permission to access the secret.
Why this is correct
To retrieve credentials dynamically, the application must use the Secrets Manager API to fetch the secret at runtime. This requires code changes to call GetSecretValue and appropriate IAM permissions for the EC2 instance role to access the secret. This approach eliminates hardcoded credentials and allows automatic rotation to take effect without application changes.
- ✗
Store the credentials in AWS Systems Manager Parameter Store as a SecureString parameter and modify the application to retrieve them from there.
Why it's wrong here
While Parameter Store can store secrets, it does not natively support automatic rotation like Secrets Manager. The requirement is to use Secrets Manager with rotation. Switching to Parameter Store would not meet the rotation requirement and would require additional custom rotation logic. Therefore, this is not the correct solution.
- ✗
Configure the application to read the credentials from an environment variable that is updated by the rotation Lambda function.
Why it's wrong here
Environment variables are static at instance launch and cannot be updated dynamically by a Lambda function without restarting the instance. The rotation Lambda updates the secret in Secrets Manager, not the environment variables. This approach would still require hardcoding or manual intervention, and does not provide dynamic retrieval.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.