Question 1 · choose 1
An application on a large fleet reads database credentials from AWS Secrets Manager and caches them for several minutes. The secret rotates every 30 days. During rotation some servers fail to connect until their cache refreshes. The team wants rotation without these failures. What should the team do?
- ASwitch to the alternating users rotation strategy
- BRotate the secret every four hours so that caches stay recent
- CMove the credentials to Parameter Store SecureString parameters
- DKeep single user rotation and turn off caching in the application
Show the answer and why
ASwitch to the alternating users rotation strategy
Correct
Alternating users keeps two valid users and updates one at a time, so cached credentials stay valid; the superuser secret is used to clone the user.
BRotate the secret every four hours so that caches stay recent
Incorrect
More frequent rotation creates more rotation windows and more of the same failures.
CMove the credentials to Parameter Store SecureString parameters
Incorrect
Parameter Store does not rotate database credentials for you, so the team loses rotation instead of fixing it.
DKeep single user rotation and turn off caching in the application
Incorrect
With single user rotation, there is still a window in which the old password no longer works and new connections can be denied.
Single user rotation is simple but has a brief window of denied connections; alternating users is the strategy for high availability.
AWS documentation