Courseiva
Security and Compliance →mediumMultiple Choice

SOA-C02 Security and Compliance Practice Question

A company stores database credentials in AWS Secrets Manager. The security policy requires that the credentials be rotated automatically every 30 days. Which action should the SysOps administrator take to enforce this requirement?

⚠ Common exam trap

Watch out — candidates often think any automated scheduling (like CloudWatch Events) is sufficient, but AWS Secrets Manager's native rotation feature is the correct and simplest way to enforce automatic rotation without custom infrastructure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable automatic rotation in the Secrets Manager console and specify a rotation interval of 30 days using a Lambda rotation function.

AWS Secrets Manager natively supports automatic rotation using a Lambda function. By enabling automatic rotation in the console and specifying a 30-day interval, the administrator meets the security policy without manual intervention. Secrets Manager handles the rotation schedule and invokes the Lambda function automatically.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure an AWS Lambda function to rotate the secret and set a CloudWatch Events rule to trigger it every 30 days.

    Why it's wrong here

    An AWS Lambda function with a CloudWatch Events rule can rotate a secret, but this approach lacks the built-in scheduling and lifecycle management that Secrets Manager’s automatic rotation feature provides. The requirement is for automatic rotation every 30 days, which Secrets Manager natively supports by attaching a rotation configuration and setting a rotation interval. This option is tempting because Lambda is a common tool for custom rotation logic, and CloudWatch Events can trigger it on a schedule, which would be correct if the rotation needed custom orchestration outside Secrets Manager’s native capabilities.

  • ✓

    Enable automatic rotation in the Secrets Manager console and specify a rotation interval of 30 days using a Lambda rotation function.

    Why this is correct

    Enabling automatic rotation in Secrets Manager is the native solution: you configure the secret's rotation configuration to invoke a dedicated Lambda function (the 'rotation function') that creates new secret versions and updates the resource or database password. Secrets Manager then runs that Lambda on a schedule, and specifying a rotation interval of 30 days gives you exactly the required cadence without building your own scheduler. This approach also integrates with IAM and CloudTrail for permission enforcement and auditability, so the rotation cycle is fully managed rather than custom-coded.

  • ✗

    Use AWS Systems Manager Parameter Store to store the credentials and configure a State Manager association for rotation.

    Why it's wrong here

    SSM Parameter Store cannot rotate credentials automatically because it has no built-in rotation lifecycle or scheduler. While a State Manager association could run an SSM document that invokes a script or Lambda to change the password, you would have to construct the entire rotation pipeline yourself, including version management, error handling, and cross-Service updates. Parameter Store also lacks Secrets Manager's native integration with IAM roles and secrets-specific features like automatic generation of random secrets, making this a non-optimal and needlessly complex alternative.

  • ✗

    Create an IAM policy that forces users to rotate the secret manually every 30 days.

    Why it's wrong here

    An IAM policy can only control who is allowed to call 'RotateSecret' (or update the secret) — it cannot force a human actually to perform the action or schedule the rotation. IAM is an authorization mechanism, not a workflow engine; there is no policy syntax that triggers an action on a recurring 30-day basis or that revokes access when the secret is stale. Manual rotation remains optional and error-prone, so it fails the requirement for automatic, time-based rotation.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SOA-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company wants to securely store secrets such as database credentials and API keys used by applications running on Amazon EC2. Which AWS service should be used to manage and rotate these secrets automatically?

easy
  • A.AWS Identity and Access Management (IAM)
  • ✓ B.AWS Secrets Manager
  • C.AWS Key Management Service (KMS)
  • D.AWS Systems Manager Parameter Store

Why B: AWS Secrets Manager is designed to securely store, manage, and automatically rotate secrets such as database credentials and API keys. It integrates with AWS services like RDS, Redshift, and DocumentDB to provide built-in rotation. This makes it the correct choice for managing and rotating secrets automatically.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.