SCS-C02 Management and Security Governance Practice Question
A company uses AWS Secrets Manager to store database credentials. The security team needs to ensure that secrets are automatically rotated every 30 days. Which configuration should be used?
⚠ Common exam trap
It's easy for candidates to confuse setting an expiration date (Option C) with automatic rotation, but expiration only triggers deletion or recreation, not the seamless, scheduled credential update that a Lambda-based rotation provides.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable automatic rotation using an AWS Lambda function.
AWS Secrets Manager provides a built-in mechanism to automatically rotate secrets using an AWS Lambda function. By configuring a rotation schedule (e.g., every 30 days), Secrets Manager invokes the Lambda function to create a new version of the secret and update the database credentials, ensuring compliance without manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Manually update the secret in Secrets Manager every 30 days.
Why it's wrong here
This approach is not a rotation mechanism; it introduces human intervention into a security control that should be fully automated. A manual update also risks credential drift, missed deadlines, or inconsistent password complexity, and it still doesn't configure Secrets Manager to call a Lambda function to change the database password. Secrets Manager's built-in rotation is intended to remove this manual burden, so any manual step leaves the system vulnerable to human error and gaps in the rotation schedule.
- ✗
Use Amazon Macie to detect when secrets are stale.
Why it's wrong here
Amazon Macie is a fully managed data security service that uses machine learning to discover and classify sensitive data in Amazon S3 buckets. It does not scan AWS Secrets Manager, does not detect credential age or staleness, and has no integration with the Secrets Manager rotation lifecycle. Using Macie for stale-secret detection is outside its purpose and would never trigger a rotation event, so it fails to address the requirement for automated credential rotation.
- ✗
Set an expiration date on the secret and recreate it.
Why it's wrong here
An expiration date on a secret in Secrets Manager only schedules a deletion window after which the secret is permanently removed; it does not trigger rotation, modify the database password, or create a new secret version automatically. The secret would still need to be manually recreated and the database credential changed independently, which leaves an open window where the secret expires but the resource still uses stale credentials. This option conflates expiration with rotation, and it does not leverage the required Lambda-based rotation mechanism.
- ✓
Enable automatic rotation using an AWS Lambda function.
Why this is correct
Secrets Manager natively supports automatic rotation by invoking an AWS Lambda function that updates the secret and the database credential in a coordinated fashion. The Lambda function follows the rotation schedule you configure (for example, every 30 days) and uses staged steps to ensure the secret is valid before promoting it, while also updating the target database. This fully automates the credential lifecycle, eliminates manual intervention, and is the correct way to enforce periodic rotation for database credentials stored in Secrets Manager.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.