AWS Certified SysOps Administrator – AssociateSecurity and ComplianceEasy
A company is using AWS Secrets Manager to store database credentials. The security team wants to ensure that applications retrieve these secrets securely and that the secrets are automatically rotated every 90 days without requiring manual intervention. Which feature of AWS Secrets Manager should the SysOps administrator configure?
- AIntegrate with AWS Key Management Service (KMS) for encryption.
- BEnable automatic rotation for the secrets and configure a rotation interval.
- CSet a resource-based policy to control access to the secrets.
- DImplement client-side encryption for secrets before storing them.
Show answer & explanationAnswer & explanation
Correct answer: B. Enable automatic rotation for the secrets and configure a rotation interval.
AWS Secrets Manager has a built-in feature for automatic secret rotation. By enabling this and configuring a rotation interval (e.g., 90 days), Secrets Manager can automatically update the secret in the database and then update the stored secret value, eliminating manual intervention.
Why the other options are wrong
- A. Secrets Manager already integrates with KMS for encryption at rest; this is a foundational security feature, not the mechanism for automatic rotation.
- C. Resource-based policies control access, which is important for security, but doesn't address automatic rotation.
- D. Client-side encryption is not a native feature of Secrets Manager for managed rotation; Secrets Manager encrypts secrets at rest and in transit by default.
AWS Secrets Manager Automatic Rotation
AWS Secrets Manager's automatic rotation feature allows you to automatically update stored secrets on a scheduled basis, improving security by regularly changing credentials without manual effort.
- Supports various secret types (database credentials, API keys).
- Uses AWS Lambda functions for custom rotation logic.
- Helps meet compliance requirements for regular credential changes.
- Reduces the risk of compromised long-lived credentials.
Memory trick: Secrets Manager: Store, Rotate, Access Securely.