A company has a legacy application that requires access to an S3 bucket using an IAM user's access keys. The security team wants to rotate the access keys every 90 days automatically. What is the MOST efficient way to achieve this?
AWS Secrets Manager natively supports automatic rotation for IAM user access keys: you configure a rotation schedule (e.g., every 30 or 90 days), and the service creates a new access key, updates the secret with the new credentials, and deletes the old key after a safe handoff—all with versioning so you can stage the new secret separately from the current one. It does not require you to write any custom scheduling code because Secrets Manager uses an AWS-provided Lambda rotation function template for IAM user keys, and it can alternate between two active keys to avoid downtime for downstream systems. This directly meets the need to 'require access to the service' without manual intervention, and it also gives you fine-grained IAM permissions to control who can access or rotate the secret, plus CloudTrail audit logs of rotation events.
Why this answer
AWS Secrets Manager provides built-in automatic rotation for IAM user access keys, allowing you to set a 90-day rotation schedule without custom code. Option A is incorrect because while AWS Lambda with a scheduled CloudWatch Events rule could rotate keys, it requires custom code and is less efficient than the managed rotation in Secrets Manager. Option B is incorrect because a script on an EC2 instance using cron would require additional infrastructure and maintenance.
Option D is incorrect because there is no built-in IAM access key rotation in the IAM console; you must manually rotate keys each time.