A company uses AWS Secrets Manager to store database credentials. They need to rotate the secrets automatically every 30 days. Which rotation strategy should they use?
Enabling automatic rotation in AWS Secrets Manager and specifying a Lambda rotation function is the correct approach. Secrets Manager invokes the Lambda function on a configurable schedule (e.g., every 30 days), and the function follows the rotation protocol—creating a new credential, updating the database user/password, and storing the new value as a version of the secret. This allows applications to automatically retrieve the new credential via the secret ARN while keeping the database credential synchronized, and it supports multi-user or single-user rotation strategies.
Why this answer
AWS Secrets Manager natively supports automatic rotation of secrets, and you must specify an AWS Lambda function to perform the rotation logic (e.g., updating the database password and storing the new secret). This ensures the secret is rotated on a schedule (every 30 days) without manual intervention, meeting the requirement for automated rotation.
Exam trap
The trap here is that candidates may confuse AWS Systems Manager Parameter Store with Secrets Manager, thinking Parameter Store can also rotate secrets automatically, or they may incorrectly assume AWS Config rules can schedule rotations, when in fact only Secrets Manager with a Lambda function provides native automatic rotation.
How to eliminate wrong answers
Option A is wrong because AWS Systems Manager Parameter Store does not have built-in automatic rotation capabilities; it is a parameter store, not a secrets rotation service, and would require custom automation to rotate secrets. Option B is wrong because manually updating the secret every 30 days is not automated and defeats the purpose of using Secrets Manager for rotation; it introduces human error and operational overhead. Option D is wrong because AWS Config rules are used for compliance evaluation and remediation, not for scheduling or executing secret rotation; they can trigger a Lambda function for remediation but are not designed as a rotation scheduler.