AWS Certified DevOps Engineer – ProfessionalSecurity and ComplianceMedium

A DevOps team is managing a critical application that uses Amazon RDS for its database. The application needs to connect to the database securely, and the security team requires that all database access credentials are automatically rotated every 90 days. Which AWS service combination would BEST meet this requirement with minimal operational overhead?

  1. AAWS Secrets Manager to store and rotate credentials, integrated with AWS Lambda to update the application.
  2. BStore credentials in an encrypted S3 bucket, and use a cron job on an EC2 instance to rotate and update.
  3. CIAM roles for EC2 instances to access RDS, and manually rotate the IAM role's access keys every 90 days.
  4. DAWS Systems Manager Parameter Store to store credentials, with a CloudWatch Event triggering a Lambda function for rotation.
Show answer & explanation

Correct answer: A. AWS Secrets Manager to store and rotate credentials, integrated with AWS Lambda to update the application.

AWS Secrets Manager is specifically designed for storing and automatically rotating database credentials, including those for Amazon RDS. It integrates directly with RDS and Lambda for seamless rotation and application updates, offering the lowest operational overhead for this task.

Why the other options are wrong

  • B. Using S3 and a cron job is a highly manual and less secure approach compared to Secrets Manager's specialized capabilities.
  • C. IAM roles are for EC2 access to services, not for database user credentials, and rotating IAM role access keys is not the same as rotating database user passwords.
  • D. Parameter Store can store secrets, but it does not natively support automated rotation for RDS credentials, requiring more custom development.

Secrets Manager for RDS Rotation

AWS Secrets Manager automates the storage, retrieval, and rotation of database credentials for services like Amazon RDS, enhancing security and reducing operational burden.

  • Native integration with RDS for rotation.
  • Can use Lambda functions for custom rotation logic.
  • Provides API for application credential retrieval.

Memory trick: To 'spin' 'secrets' for 'RDS', 'Secrets Manager' is the 'key'.

More Security and Compliance questions