Ultimate access to all questions.
A company is adopting a serverless architecture using AWS Lambda to interact with a Microsoft SQL Server database on Amazon RDS. They maintain distinct development and production environments, including database clones. Developers have access to the development database credentials, but production database credentials must be encrypted with a key accessible only to the IT security team's IAM group. This key requires regular rotation. What is the optimal strategy for a solutions architect to secure the production database credentials?