Question 1 · choose 1
An AWS Glue job connects to an Amazon RDS for PostgreSQL database with a user name and password that are typed into the job's parameters. Security requires that the password be stored encrypted, rotated automatically every 30 days, and picked up by the job without redeploying it. What should a data engineer do?
- AStore the password as a SecureString parameter in Parameter Store and read it in the job script
- BKeep the credentials in a rotated AWS Secrets Manager secret used by the Glue connection
- CEncrypt the password with a KMS key and keep the ciphertext in the job parameters
- DSave the credentials in an SSE-KMS encrypted S3 object that the job reads at start-up
Show the answer and why
AStore the password as a SecureString parameter in Parameter Store and read it in the job script
Incorrect
SecureString encrypts the value, but Parameter Store does not rotate it. AWS recommends Secrets Manager for database credentials.
BKeep the credentials in a rotated AWS Secrets Manager secret used by the Glue connection
Correct
Secrets Manager stores secrets encrypted and rotates them on a schedule, and a Glue connection can read its credentials from a Secrets Manager secret, so the job always gets the current value.
CEncrypt the password with a KMS key and keep the ciphertext in the job parameters
Incorrect
The password is encrypted but never rotated, and every change would mean editing the job.
DSave the credentials in an SSE-KMS encrypted S3 object that the job reads at start-up
Incorrect
The object is encrypted at rest, but nothing rotates the password in the object and the database together.
Database credentials belong in Secrets Manager: encrypted, rotated on a schedule, and fetched at run time by services such as Glue connections.
AWS documentation