How to rotate RDS credentials with zero downtime using AWS Secrets Manager?
A company runs a serverless application on AWS. The application includes an AWS Lambda function. The Lambda function processes data and stores the data in an Amazon RDS for PostgreSQL database. A developer created a user credentials in the database for the application. The developer needs to use AWS Secrets Manager to manage the user credentials. The password must to be rotated on a regular basis. The solution needs to ensure that there is high availability and no downtime for the application during secret rotation. What should the developer do to meet these requirements?
Community Votes
69% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests understanding of the alternating users rotation strategy in AWS Secrets Manager, which maintains high availability by keeping one user active while the other is being rotated, eliminating downtime during credential updates.
This question tests the correct configuration of AWS Secrets Manager for rotating Amazon RDS for PostgreSQL credentials with high availability and no downtime. The community consensus favors the alternating users rotation strategy combined with AWS-managed automatic rotation.
Many candidates choose option B (managed rotation with alternating users) because they believe 'managed rotation' is the correct AWS terminology. However, AWS documentation explicitly recommends 'automatic rotation' over 'managed rotation' as it eliminates the need to create and manage custom Lambda functions for rotation logic.
Community Discussion (10 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Understanding AWS Secrets Manager Rotation Strategies
AWS Secrets Manager provides two primary rotation strategies for database credentials:
Single User vs. Alternating Users Strategy
The single user rotation strategy updates credentials for a single database user. During rotation, there's a brief window where the application might experience connection failures because the credentials are being changed.
The alternating users rotation strategy creates two database users with identical permissions. While one user remains active and serving application traffic, Secrets Manager rotates the credentials for the inactive user, then switches the application to use the newly rotated credentials. This ensures zero downtime and high availability during rotation.
Automatic vs. Managed Rotation
AWS documentation explicitly states: "We strongly recommend that you use automatic rotation instead of managed rotation." Automatic rotation eliminates the need to create and manage Lambda functions to update secrets in AWS Secrets Manager or the database. It's a fully managed service that handles the entire rotation process.
Managed rotation requires you to specify custom rotation Lambda functions, adding operational overhead and complexity. While both approaches can work, automatic rotation is the recommended best practice.
Why Option D is Correct
Option D combines both best practices:
- Automatic rotation: Fully managed by AWS, no custom Lambda functions needed
- Alternating users strategy: Ensures high availability with no downtime during rotation
Why Other Options Are Wrong
- Option A: Single user strategy causes brief downtime during rotation
- Option B: While alternating users is correct, managed rotation requires custom Lambda functions and is not the recommended approach
- Option C: Single user strategy doesn't meet the high availability requirement
Official Reference
Exam Strategy
When AWS documentation explicitly recommends one approach over another (like automatic vs. managed rotation), always choose the recommended approach on the exam. Look for keywords like 'high availability' and 'no downtime' as strong indicators for the alternating users strategy.
Related Analysis
Practice All DVA-C02 Questions
Access 100 questions with complete answers and detailed explanations.
View Full DVA-C02 Practice Test →