Question 1 · choose 1
A security review found that 200 application servers keep the password of an Amazon RDS for SQL Server database in a configuration file. The password has not changed in two years. The company wants the password out of the files, rotated every 30 days automatically, and applications that keep working during rotation. Which solution meets these requirements?
- AStore the password as a SecureString parameter in Parameter Store and have each server read it at startup
- BKeep the credentials in AWS Secrets Manager with 30-day automatic rotation and fetch the secret at runtime
- CEncrypt the configuration files with an AWS KMS key and replace the files on every server each month
- DPut the password in an environment variable of each server through the instance user data
Show the answer and why
AStore the password as a SecureString parameter in Parameter Store and have each server read it at startup
Incorrect
SecureString parameters are encrypted, but Parameter Store has no built-in rotation, so the 30-day rotation would need custom code.
BKeep the credentials in AWS Secrets Manager with 30-day automatic rotation and fetch the secret at runtime
Correct
Secrets Manager can rotate Amazon RDS credentials automatically on a schedule, updating both the secret and the database, and applications that fetch the secret when they connect pick up the new value.
CEncrypt the configuration files with an AWS KMS key and replace the files on every server each month
Incorrect
The password stays in files on 200 servers, and changing it every month depends on a manual or custom process.
DPut the password in an environment variable of each server through the instance user data
Incorrect
AWS advises against keeping passwords in user data, because anyone with access to the instance can read it, and nothing would rotate the password.
"Out of the code, rotated on a schedule" is Secrets Manager rotation with applications that read the secret at runtime.
AWS documentation
- Rotate AWS Secrets Manager secrets (opens in a new tab)
- Set up automatic rotation for Amazon RDS, Amazon Aurora, Amazon Redshift, or Amazon DocumentDB secrets (opens in a new tab)
- Get secrets from AWS Secrets Manager (opens in a new tab)
- Use AWS Secrets Manager secrets in Parameter Store (opens in a new tab)
- Use instance metadata to manage your EC2 instance (opens in a new tab)
- What is AWS Secrets Manager? (opens in a new tab)