Question 291 of 988
AWS Secrets Manager vs Parameter Store: Which Service Automatically Rotates Secrets?
A company runs a microservices-based application on Amazon ECS. The application stores database credentials and API keys in plaintext configuration files that are baked into container images. A security audit reveals that this practice violates the company's compliance policy, which mandates that secrets must be stored separately from code, centrally managed, and automatically rotated every 90 days. Which AWS service should the company use to meet these requirements?
Quick Answer
The answer is AWS Secrets Manager. This service is the correct choice because it is purpose-built to store, manage, and automatically rotate secrets like database credentials and API keys, meeting the compliance requirement for rotation every 90 days through built-in integrations with AWS RDS, Redshift, and DocumentDB, or via custom Lambda functions. On the AWS Certified Cloud Practitioner CLF-C02 exam, this question tests your understanding of the key difference between Secrets Manager and Parameter Store: while both can store secrets, only Secrets Manager offers native automatic rotation. A common trap is choosing Parameter Store because it is cheaper, but the exam emphasizes that rotation is a core feature of Secrets Manager. Remember the memory tip: “Secrets Manager rotates; Parameter Store stores.”
⚠ Common exam trap
Candidates often confuse AWS Secrets Manager with AWS Systems Manager Parameter Store, assuming both offer automatic rotation, but Parameter Store lacks native rotation capabilities and is primarily for configuration data, not secrets lifecycle management.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Secrets Manager
AWS Secrets Manager is the correct choice because it is designed specifically for storing, managing, and automatically rotating database credentials, API keys, and other secrets throughout their lifecycle. It meets the compliance requirements by storing secrets separately from code, providing a central management console and API, and supporting automatic rotation every 90 days via built-in integration with AWS RDS, Redshift, and DocumentDB, or custom Lambda functions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Key Management Service (AWS KMS)
Why it's wrong here
AWS KMS is for creating and controlling encryption keys, not for storing secrets like passwords and API keys. It does not provide automatic rotation of secrets.
When this WOULD be correct
A company needs to encrypt data at rest in Amazon S3 using customer-managed keys with automatic annual rotation. AWS KMS would be the correct service for managing the encryption keys.
- ✗
AWS CloudHSM
Why it's wrong here
AWS CloudHSM offers dedicated hardware security modules for generating and storing encryption keys, but it is not a secrets management service and does not support automatic rotation of application secrets.
When this WOULD be correct
A company needs to generate and store cryptographic keys in a dedicated, FIPS 140-2 Level 3 validated hardware security module (HSM) for compliance, and does not require automatic rotation of application secrets.
- ✓
AWS Secrets Manager
Why this is correct
AWS Secrets Manager is purpose-built for storing, managing, and automatically rotating secrets such as database credentials and API keys. It integrates with Lambda to perform rotation on a schedule and with RDS for automatic credential updates, meeting the compliance requirements.
- ✗
AWS Systems Manager Parameter Store
Why it's wrong here
AWS Systems Manager Parameter Store fails to meet the requirement for automatic secret rotation every 90 days, as it does not natively provide this functionality for database credentials or API keys. While it effectively separates secrets from code and offers central management, making it a suitable choice for storing static configuration parameters or secrets that do not require lifecycle management, it lacks the built-in automated rotation mechanisms essential for this compliance policy.
When this WOULD be correct
A company needs to store configuration data (e.g., database URLs, AMI IDs) that does not require automatic rotation, and they want a free, scalable service integrated with EC2, ECS, and Lambda for parameter management.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CLF-C02 exam frequently reuses these exact scenarios with slightly different constraints.
✓AWS Secrets ManagerCorrect answer▾
Why this is correct
AWS Secrets Manager is purpose-built for storing, managing, and automatically rotating secrets such as database credentials and API keys. It integrates with Lambda to perform rotation on a schedule and with RDS for automatic credential updates, meeting the compliance requirements.
✗AWS Key Management Service (AWS KMS)Wrong answer — click to see why▾
Why this is wrong here
AWS KMS is a key management service for creating and controlling encryption keys, not for storing secrets like database credentials or API keys. It does not provide automatic rotation of secrets or a centralized secret store.
★ When this WOULD be the correct answer
A company needs to encrypt data at rest in Amazon S3 using customer-managed keys with automatic annual rotation. AWS KMS would be the correct service for managing the encryption keys.
Why candidates choose this
Candidates may confuse 'managing secrets' with 'managing encryption keys,' assuming KMS can store secrets because it handles keys and encryption.
✗AWS CloudHSMWrong answer — click to see why▾
Why this is wrong here
AWS CloudHSM provides hardware security modules for cryptographic key storage but does not offer automatic secret rotation or centralized management of application secrets like database credentials and API keys.
★ When this WOULD be the correct answer
A company needs to generate and store cryptographic keys in a dedicated, FIPS 140-2 Level 3 validated hardware security module (HSM) for compliance, and does not require automatic rotation of application secrets.
Why candidates choose this
Candidates may confuse CloudHSM's key storage capabilities with secret management, assuming it can handle credentials and API keys similarly to Secrets Manager.
✗AWS Systems Manager Parameter StoreWrong answer — click to see why▾
Why this is wrong here
AWS Systems Manager Parameter Store does not support automatic rotation of secrets; it requires custom solutions (e.g., Lambda) to rotate secrets, whereas the compliance policy mandates automatic rotation every 90 days.
★ When this WOULD be the correct answer
A company needs to store configuration data (e.g., database URLs, AMI IDs) that does not require automatic rotation, and they want a free, scalable service integrated with EC2, ECS, and Lambda for parameter management.
Why candidates choose this
Candidates may confuse Parameter Store with Secrets Manager because both can store secrets, but they overlook the automatic rotation requirement, which is a key differentiator in this question.
Analysis generated from the official CLF-C02blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
About these practice questions
Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
3 more ways this is tested on CLF-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company runs a web application on Amazon EC2 instances behind an Application Load Balancer. The application connects to an Amazon RDS for MySQL database. The database password is currently hardcoded in the application configuration file, and the security team is concerned about the risk of exposure. The company wants to remove the hardcoded credential and instead have the application retrieve the database password securely at runtime. Additionally, the security team requires that the password be automatically rotated every 90 days without any manual intervention or custom scripting. Which AWS service should the company use to meet these requirements?
medium- A.AWS Systems Manager Parameter Store (SecureString parameters)
- B.AWS Key Management Service (AWS KMS)
- ✓ C.AWS Secrets Manager
- D.AWS Identity and Access Management (IAM) roles for Amazon EC2
Why C: AWS Secrets Manager is the correct choice because it is purpose-built for securely storing, retrieving, and automatically rotating database credentials (including RDS for MySQL) without custom code. It supports native, automatic rotation of secrets every 90 days via a built-in Lambda rotation function, meeting the security team's requirement for zero manual intervention. Unlike Parameter Store, Secrets Manager provides automatic rotation out of the box, which is the key differentiator here.
Variation 2. A company runs a web application that connects to an Amazon RDS for MySQL database. The security policy requires that the database password be rotated every 30 days. The development team wants a fully managed solution that automatically rotates the password, handles the update in RDS, and provides the application with the latest credentials without any code changes. The application should also continue to work during the rotation process. Which AWS service should the company use to meet these requirements?
medium- ✓ A.AWS Secrets Manager
- B.AWS Systems Manager Parameter Store
- C.AWS Key Management Service (AWS KMS)
- D.AWS Identity and Access Management (IAM)
Why A: AWS Secrets Manager is the correct choice because it provides a fully managed service for automatic password rotation every 30 days, directly integrates with Amazon RDS for MySQL to update the database credentials, and supplies the latest credentials to the application via the Secrets Manager API without requiring any code changes. The rotation process is designed to ensure application availability by using a staged rotation strategy (e.g., creating a new credential while the old one remains valid) so the application continues to work during the rotation.
Variation 3. A company uses an Amazon RDS for PostgreSQL database for its production application. The security policy requires that database passwords be rotated automatically every 90 days. The database credentials are currently stored in a configuration file on an Amazon EC2 instance. The company wants a fully managed AWS service that can securely store the credentials, automatically rotate them on a schedule, and update the RDS instance without requiring code changes to the application. Which AWS service should the company use to meet these requirements?
medium- ✓ A.AWS Secrets Manager
- B.AWS Systems Manager Parameter Store
- C.AWS Key Management Service (KMS)
- D.AWS Certificate Manager (ACM)
Why A: AWS Secrets Manager is the correct choice because it is a fully managed service designed specifically to securely store database credentials, automatically rotate them on a defined schedule (e.g., every 90 days), and natively integrate with Amazon RDS to update the password without requiring any application code changes. The application can retrieve the current credentials at runtime using the Secrets Manager API, eliminating the need for hardcoded or file-based credentials.
Last reviewed: Jun 11, 2026
This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.
Question Discussion
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
Sign in to join the discussion.