For IndividualsFor Educators
ExpertMinds LogoExpertMinds
ExpertMinds

Ace your certifications with Practice Exams and AI assistance.

  • Browse Exams
  • For Educators
  • Blog
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Support
  • AWS SAA Exam Prep
  • PMI PMP Exam Prep
  • CPA Exam Prep
  • GCP PCA Exam Prep

© 2026 TinyHive Labs. Company number 16262776.

    PracticeAWS Solutions Architect Professional (SAP-C02)AWS Solutions Architect Professional SAP-C02 Practice Exam 6Question 10
    Hard1 markMultiple Choice
    Domain 1.2: Security ControlsSecuritySecrets ManagerRDS

    AWS SAP-C02 · Question 10 · Domain 1.2: Security Controls

    An enterprise wants to centrally manage and automate the rotation of database credentials for Amazon RDS instances across 50 AWS accounts. The solution must ensure that applications can retrieve the latest credentials without code changes. Which approach is MOST architecturally sound?

    Answer options:

    A.

    Use AWS Systems Manager Parameter Store in each account. Use EventBridge to trigger Lambda for rotation.

    B.

    Use AWS Secrets Manager in a central account. Configure cross-account resource policies on the secrets. Use AWS Lambda for rotation.

    C.

    Store credentials in an encrypted Amazon S3 bucket. Use S3 Object Lock to prevent tampering.

    D.

    Use AWS KMS to encrypt credentials in application code. Rotate the KMS keys annually.

    How to approach this question

    Identify the service designed specifically for secret rotation and cross-account access.

    Full Answer

    B.Use AWS Secrets Manager in a central account. Configure cross-account resource policies on the secrets. Use AWS Lambda for rotation.✓ Correct
    AWS Secrets Manager natively supports automated rotation of RDS credentials and allows cross-account access via resource-based policies.

    Common mistakes

    Choosing Parameter Store, which lacks native rotation and cross-account resource policies.
    Question 09All questionsQuestion 11

    Practice the full AWS Solutions Architect Professional SAP-C02 Practice Exam 6

    75 questions · hints · full answers · grading

    Sign up freeTake the exam

    More questions from this exam

    Q01A global enterprise requires highly available hybrid connectivity between its on-premises data ce...HardQ02An organization has 50 VPCs across two AWS Regions connected via Transit Gateways (TGW). The TGWs...HardQ03A company uses AWS Organizations. The network team wants to share a central Transit Gateway (TGW)...MediumQ04An enterprise has on-premises data centers in the US and Europe. They want to use the AWS global ...HardQ05A company requires that all API calls to Amazon S3 from their VPC must not traverse the public in...Medium
    View all 75 questions →