Courseiva
Security and Compliance →hardMultiple Choice

SOA-C02 Practice Question: Secrets Manager automatic rotation for RDS…

An application stores its RDS PostgreSQL credentials in AWS Secrets Manager. The security policy requires credentials to be rotated every 30 days automatically. During rotation, the application must continue to serve traffic with zero downtime. The application retrieves credentials by calling GetSecretValue at the start of each database connection. What must be configured to satisfy all requirements?

⚠ Common exam trap

Watch out — candidates often think any automated rotation (like EventBridge + Lambda) suffices, but the question specifically tests the integration of Secrets Manager's native rotation with its versioning and staging labels to achieve zero downtime.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable automatic rotation in Secrets Manager with a 30-day schedule; use the AWS-provided Lambda rotation function for RDS PostgreSQL; ensure the application calls GetSecretValue per connection rather than caching credentials

AWS Secrets Manager's automatic rotation, combined with the AWS-provided Lambda rotation function for RDS PostgreSQL, ensures credentials are rotated every 30 days without manual intervention. The application's practice of calling GetSecretValue at the start of each database connection guarantees it always retrieves the current secret, avoiding stale credentials and achieving zero downtime during rotation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable automatic rotation in Secrets Manager with a 30-day schedule; use the AWS-provided Lambda rotation function for RDS PostgreSQL; ensure the application calls GetSecretValue per connection rather than caching credentials

    Why this is correct

    The AWS-provided rotation Lambda handles the full four-step lifecycle. The 30-day rotation schedule triggers the Lambda automatically. Because the application fetches credentials fresh per connection, it starts using the new credentials immediately after AWSCURRENT switches, with no restart needed. Secrets Manager's rotation is designed for zero downtime — the new password is validated on the database before the old version is retired.

  • ✗

    Rotate credentials manually every 30 days by updating the secret value in the console and restarting the application

    Why it's wrong here

    Manual rotation via the console every 30 days is not a scheduled or automated process, so it fails the requirement for automatic rotation and introduces the risk of human error—such as missing the window or generating a weak password. Updating the secret value in the console does not update the actual RDS PostgreSQL password; you'd still need to run ALTER USER or use the RDS console to change the database credential, and then you'd have a window where the secret and the database are out of sync. Restarting the application to pick up the new credentials violates the zero-downtime requirement, because a restart causes connection drops and service unavailability. In contrast, Secrets Manager's built-in rotation uses a Lambda function that atomically updates both the database and the secret, and the application can retrieve the new password on the next GetSecretValue call without a restart.

  • ✗

    Create an EventBridge scheduled rule every 30 days that triggers a Lambda to generate a new RDS password and update both the database and the secret

    Why it's wrong here

    This approach reimplements what Secrets Manager rotation already provides natively. The custom Lambda must replicate the full four-step rotation protocol correctly, handle rollback on failure, and manage the transition window between old and new passwords. Secrets Manager's built-in rotation handles all of this.

  • ✗

    Store credentials in an environment variable on the application's EC2 instance and rotate by updating the environment variable and reloading the application

    Why it's wrong here

    Environment variables are not managed by Secrets Manager, do not support automatic rotation, are not encrypted at rest by default, and appear in the EC2 console. This approach violates the Secrets Manager requirement and the zero-downtime requirement (reloading requires a restart).

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.