A company has a relational database workload that runs on Amazon Aurora MySQL. According to new compliance standards the company must rotate all database credentials every 30 days. The company needs a solution that maximizes security and minimizes development effort.
Which solution will meet these requirements?
To rotate database credentials every 30 days, the most secure and efficient solution is to store the database credentials in AWS Secrets Manager and configure automatic credential rotation for every 30 days. Secrets Manager can handle the rotation of the credentials in both the secret and the database, and it can use AWS KMS to encrypt the credentials. Option B is incorrect because it requires creating a custom Lambda function to rotate the credentials, which is more effort than using Secrets Manager. Option C is incorrect because it stores the database credentials in an environment file or a configuration file, which is less secure than using Secrets Manager. Option D is incorrect because it combines the drawbacks of option B and option C. Verified Reference:
https://docs.aws.amazon.com/secretsmanager/latest/userguide/rotating-secrets.html
https://docs.aws.amazon.com/secretsmanager/latest/userguide/rotate-secrets_turn-on-for-other.html
Telma
10 months agoJamey
10 months agoHubert
10 months agoBrittani
10 months agoJamey
10 months agoNu
10 months agoShaquana
10 months agoTwana
11 months agoSabine
11 months agoMarta
12 months agoShawnda
12 months agoMabel
1 years agoGlory
1 years agoCaprice
12 months agoLeah
12 months agoKimberlie
12 months agoLuisa
12 months agoTawna
12 months agoHorace
12 months agoLynda
12 months agoMarvel
1 years agoKirk
1 years ago