Courseiva
Data Protection →hardMultiple Choice

SCS-C02 Data Protection Practice Question

A company uses AWS Secrets Manager to store database credentials for an application running on EC2 instances. The security engineer needs to ensure that the credentials are automatically rotated every 30 days and that the application can retrieve the credentials without hardcoding them. The engineer has configured a rotation Lambda function and enabled rotation. However, the application is still using hardcoded credentials. What should the engineer do to ensure the application retrieves credentials dynamically?

⚠ Common exam trap

The trap here is thinking that enabling rotation in Secrets Manager automatically updates the application's credentials, but the application must be coded to fetch the secret dynamically.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Modify the application code to call the Secrets Manager GetSecretValue API using the AWS SDK, and grant the EC2 instance role permission to access the secret.

The application must be modified to use the Secrets Manager API to retrieve credentials at runtime. This ensures that the application always gets the current credentials after rotation. The EC2 instance role must have permissions to call GetSecretValue on the secret. This is the standard pattern for dynamic secret retrieval.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use AWS AppConfig to deploy the credentials to the EC2 instances and configure the application to read from a local file.

    Why it's wrong here

    AWS AppConfig is designed for application configuration, not for secure secret storage and rotation. Storing database credentials in AppConfig and writing them to a local file would not provide the security and automatic rotation features of Secrets Manager. This method could expose credentials and does not meet the requirement for automatic rotation.

  • ✓

    Modify the application code to call the Secrets Manager GetSecretValue API using the AWS SDK, and grant the EC2 instance role permission to access the secret.

    Why this is correct

    To retrieve credentials dynamically, the application must use the Secrets Manager API to fetch the secret at runtime. This requires code changes to call GetSecretValue and appropriate IAM permissions for the EC2 instance role to access the secret. This approach eliminates hardcoded credentials and allows automatic rotation to take effect without application changes.

  • ✗

    Store the credentials in AWS Systems Manager Parameter Store as a SecureString parameter and modify the application to retrieve them from there.

    Why it's wrong here

    While Parameter Store can store secrets, it does not natively support automatic rotation like Secrets Manager. The requirement is to use Secrets Manager with rotation. Switching to Parameter Store would not meet the rotation requirement and would require additional custom rotation logic. Therefore, this is not the correct solution.

  • ✗

    Configure the application to read the credentials from an environment variable that is updated by the rotation Lambda function.

    Why it's wrong here

    Environment variables are static at instance launch and cannot be updated dynamically by a Lambda function without restarting the instance. The rotation Lambda updates the secret in Secrets Manager, not the environment variables. This approach would still require hardcoding or manual intervention, and does not provide dynamic retrieval.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.