SOA-C02 Practice Question: Secrets Manager automatic rotation for RDS…
An application stores its RDS PostgreSQL credentials in AWS Secrets Manager. The security policy requires credentials to be rotated every 30 days automatically. During rotation, the application must continue to serve traffic with zero downtime. The application retrieves credentials by calling GetSecretValue at the start of each database connection. What must be configured to satisfy all requirements?
⚠ Common exam trap
Watch out — candidates often think any automated rotation (like EventBridge + Lambda) suffices, but the question specifically tests the integration of Secrets Manager's native rotation with its versioning and staging labels to achieve zero downtime.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable automatic rotation in Secrets Manager with a 30-day schedule; use the AWS-provided Lambda rotation function for RDS PostgreSQL; ensure the application calls GetSecretValue per connection rather than caching credentials
AWS Secrets Manager's automatic rotation, combined with the AWS-provided Lambda rotation function for RDS PostgreSQL, ensures credentials are rotated every 30 days without manual intervention. The application's practice of calling GetSecretValue at the start of each database connection guarantees it always retrieves the current secret, avoiding stale credentials and achieving zero downtime during rotation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable automatic rotation in Secrets Manager with a 30-day schedule; use the AWS-provided Lambda rotation function for RDS PostgreSQL; ensure the application calls GetSecretValue per connection rather than caching credentials
Why this is correct
The AWS-provided rotation Lambda handles the full four-step lifecycle. The 30-day rotation schedule triggers the Lambda automatically. Because the application fetches credentials fresh per connection, it starts using the new credentials immediately after AWSCURRENT switches, with no restart needed. Secrets Manager's rotation is designed for zero downtime — the new password is validated on the database before the old version is retired.
- ✗
Rotate credentials manually every 30 days by updating the secret value in the console and restarting the application
Why it's wrong here
Manual rotation via the console every 30 days is not a scheduled or automated process, so it fails the requirement for automatic rotation and introduces the risk of human error—such as missing the window or generating a weak password. Updating the secret value in the console does not update the actual RDS PostgreSQL password; you'd still need to run ALTER USER or use the RDS console to change the database credential, and then you'd have a window where the secret and the database are out of sync. Restarting the application to pick up the new credentials violates the zero-downtime requirement, because a restart causes connection drops and service unavailability. In contrast, Secrets Manager's built-in rotation uses a Lambda function that atomically updates both the database and the secret, and the application can retrieve the new password on the next GetSecretValue call without a restart.
- ✗
Create an EventBridge scheduled rule every 30 days that triggers a Lambda to generate a new RDS password and update both the database and the secret
Why it's wrong here
This approach reimplements what Secrets Manager rotation already provides natively. The custom Lambda must replicate the full four-step rotation protocol correctly, handle rollback on failure, and manage the transition window between old and new passwords. Secrets Manager's built-in rotation handles all of this.
- ✗
Store credentials in an environment variable on the application's EC2 instance and rotate by updating the environment variable and reloading the application
Why it's wrong here
Environment variables are not managed by Secrets Manager, do not support automatic rotation, are not encrypted at rest by default, and appear in the EC2 console. This approach violates the Secrets Manager requirement and the zero-downtime requirement (reloading requires a restart).
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.