How to rotate RDS credentials with zero downtime using AWS Secrets Manager?

A company runs a serverless application on AWS. The application includes an AWS Lambda function. The Lambda function processes data and stores the data in an Amazon RDS for PostgreSQL database. A developer created a user credentials in the database for the application. The developer needs to use AWS Secrets Manager to manage the user credentials. The password must to be rotated on a regular basis. The solution needs to ensure that there is high availability and no downtime for the application during secret rotation. What should the developer do to meet these requirements?

  1. Configure managed rotation with the single user rotation strategy.
  2. Configure managed rotation with the alternating users rotation strategy.
  3. Configure automatic rotation with the single user rotation strategy.
  4. Configure automatic rotation with the alternating users rotation strategy. Source Reference Answer

Community Votes

D
69%
B
31%

69% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests understanding of the alternating users rotation strategy in AWS Secrets Manager, which maintains high availability by keeping one user active while the other is being rotated, eliminating downtime during credential updates.

This question tests the correct configuration of AWS Secrets Manager for rotating Amazon RDS for PostgreSQL credentials with high availability and no downtime. The community consensus favors the alternating users rotation strategy combined with AWS-managed automatic rotation.

Many candidates choose option B (managed rotation with alternating users) because they believe 'managed rotation' is the correct AWS terminology. However, AWS documentation explicitly recommends 'automatic rotation' over 'managed rotation' as it eliminates the need to create and manage custom Lambda functions for rotation logic.

Community Discussion (10 comments)

tgv 👍 15 Selected: D
Managed rotation vs. automatic rotation: Managed rotation requires manual intervention to specify when a secret should be rotated. This doesn't meet the requirement of automated password rotation on a regular basis. Automatic rotation automatically rotates secrets based on a defined schedule, meeting the requirement for regular password changes. Single user vs. alternating users: Single user rotation means there is only one set of credentials. Rotating this would cause downtime as the application needs to update its connection information. Alternating users rotation uses two sets of credentials. Only one is active at a time. When it's time to rotate, the inactive set is rotated, and then the application switches to using that set, avoiding downtime
Arad 👍 1 Selected: B
B is the correct answer. D is wrong because automatic rotation requires the developer to write and manage custom rotation logic. Using managed rotation is simpler and more operationally efficient.
bp07 👍 1 Selected: B
"Automatic rotation" is not a distinct concept in AWS Secrets Manager; rotation is always "managed." This option likely refers to the alternating strategy but does not add clarity compared to managed rotation.
Saurabh04 👍 1 Selected: B
Automatic rotation does not address the high availability requirement. If the rotation process causes downtime, it could impact our application's stability
albert_kuo 👍 1 Selected: B
B. Configure managed rotation with the alternating users rotation strategy.
65703c1 👍 1 Selected: D
D is the correct answer.
Abdullah22 👍 2 Selected: D
Automatic Rotation We strongly recommend that you use automatic rotation instead of managed rotation. Automatic rotation simplifies the rotation process and offers several advantages over managed rotation, including: It eliminates the need to create and manage Lambda functions to update the secret in AWS Secrets Manager or the database. It supports the alternating users rotation strategy, which is no longer supported for managed rotation. (Source: AWS Secrets Manager documentation: https://docs.aws.amazon.com/secretsmanager/latest/userguide/rotating-secrets.html)
SerialiDr 👍 2 Selected: B
Using AWS Secrets Manager's managed rotation with the alternating users rotation strategy is ideal for databases like Amazon RDS for PostgreSQL. This strategy involves creating a second user in the database with the same permissions as the original user. During rotation, Secrets Manager switches between these two users, updating the credentials for the inactive user and then making it the active user for subsequent connections. This approach minimizes the risk of downtime because the application can continue to use the currently active credentials while the other set is being rotated. It also ensures that credentials are regularly updated, enhancing security without disrupting database access.
KarBiswa 👍 2 Selected: D
https://docs.aws.amazon.com/secretsmanager/latest/userguide/tutorials_rotation-alternating.html#:~:text=This%20strategy%20is%20a%20good%20choice%20if%20you%20need%20high%20availability%20for%20your%20secret%2C%20because%20one%20of%20the%20alternating%20users%20has%20current%20credentials%20to%20the%20database%20while%20the%20other%20one%20is%20being%20updated.%20For%20more
CrescentShared 👍 3 Selected: B
Both B and D options involve using the alternating users rotation strategy, which is suitable for ensuring high availability and no downtime during secret rotation. The difference between "managed rotation" and "automatic rotation" is mostly semantic in this context, as both terms refer to the capability of AWS Secrets Manager to automatically rotate the secret. The more common terminology used in the context of AWS Secrets Manager is "managed rotation," so option B is often preferred.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Understanding AWS Secrets Manager Rotation Strategies

AWS Secrets Manager provides two primary rotation strategies for database credentials:

Single User vs. Alternating Users Strategy

The single user rotation strategy updates credentials for a single database user. During rotation, there's a brief window where the application might experience connection failures because the credentials are being changed.

The alternating users rotation strategy creates two database users with identical permissions. While one user remains active and serving application traffic, Secrets Manager rotates the credentials for the inactive user, then switches the application to use the newly rotated credentials. This ensures zero downtime and high availability during rotation.

Automatic vs. Managed Rotation

AWS documentation explicitly states: "We strongly recommend that you use automatic rotation instead of managed rotation." Automatic rotation eliminates the need to create and manage Lambda functions to update secrets in AWS Secrets Manager or the database. It's a fully managed service that handles the entire rotation process.

Managed rotation requires you to specify custom rotation Lambda functions, adding operational overhead and complexity. While both approaches can work, automatic rotation is the recommended best practice.

Why Option D is Correct

Option D combines both best practices:

  • Automatic rotation: Fully managed by AWS, no custom Lambda functions needed
  • Alternating users strategy: Ensures high availability with no downtime during rotation

Why Other Options Are Wrong

  • Option A: Single user strategy causes brief downtime during rotation
  • Option B: While alternating users is correct, managed rotation requires custom Lambda functions and is not the recommended approach
  • Option C: Single user strategy doesn't meet the high availability requirement
The community discussion reveals confusion about terminology, but AWS documentation clearly favors automatic rotation as the modern, recommended approach for database credential rotation.

Official Reference

Exam Strategy

When AWS documentation explicitly recommends one approach over another (like automatic vs. managed rotation), always choose the recommended approach on the exam. Look for keywords like 'high availability' and 'no downtime' as strong indicators for the alternating users strategy.

Related Analysis

Practice All DVA-C02 Questions

Access 100 questions with complete answers and detailed explanations.

View Full DVA-C02 Practice Test →

← Back to DVA-C02 Study Guide