Courseiva
Question 291 of 988
Security and CompliancemediumMultiple ChoiceObjective-mapped

AWS Secrets Manager vs Parameter Store: Which Service Automatically Rotates Secrets?

A company runs a microservices-based application on Amazon ECS. The application stores database credentials and API keys in plaintext configuration files that are baked into container images. A security audit reveals that this practice violates the company's compliance policy, which mandates that secrets must be stored separately from code, centrally managed, and automatically rotated every 90 days. Which AWS service should the company use to meet these requirements?

Quick Answer

The answer is AWS Secrets Manager. This service is the correct choice because it is purpose-built to store, manage, and automatically rotate secrets like database credentials and API keys, meeting the compliance requirement for rotation every 90 days through built-in integrations with AWS RDS, Redshift, and DocumentDB, or via custom Lambda functions. On the AWS Certified Cloud Practitioner CLF-C02 exam, this question tests your understanding of the key difference between Secrets Manager and Parameter Store: while both can store secrets, only Secrets Manager offers native automatic rotation. A common trap is choosing Parameter Store because it is cheaper, but the exam emphasizes that rotation is a core feature of Secrets Manager. Remember the memory tip: “Secrets Manager rotates; Parameter Store stores.”

⚠ Common exam trap

Candidates often confuse AWS Secrets Manager with AWS Systems Manager Parameter Store, assuming both offer automatic rotation, but Parameter Store lacks native rotation capabilities and is primarily for configuration data, not secrets lifecycle management.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

AWS Secrets Manager

AWS Secrets Manager is the correct choice because it is designed specifically for storing, managing, and automatically rotating database credentials, API keys, and other secrets throughout their lifecycle. It meets the compliance requirements by storing secrets separately from code, providing a central management console and API, and supporting automatic rotation every 90 days via built-in integration with AWS RDS, Redshift, and DocumentDB, or custom Lambda functions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • AWS Key Management Service (AWS KMS)

    Why it's wrong here

    AWS KMS is for creating and controlling encryption keys, not for storing secrets like passwords and API keys. It does not provide automatic rotation of secrets.

    When this WOULD be correct

    A company needs to encrypt data at rest in Amazon S3 using customer-managed keys with automatic annual rotation. AWS KMS would be the correct service for managing the encryption keys.

  • AWS CloudHSM

    Why it's wrong here

    AWS CloudHSM offers dedicated hardware security modules for generating and storing encryption keys, but it is not a secrets management service and does not support automatic rotation of application secrets.

    When this WOULD be correct

    A company needs to generate and store cryptographic keys in a dedicated, FIPS 140-2 Level 3 validated hardware security module (HSM) for compliance, and does not require automatic rotation of application secrets.

  • AWS Secrets Manager

    Why this is correct

    AWS Secrets Manager is purpose-built for storing, managing, and automatically rotating secrets such as database credentials and API keys. It integrates with Lambda to perform rotation on a schedule and with RDS for automatic credential updates, meeting the compliance requirements.

  • AWS Systems Manager Parameter Store

    Why it's wrong here

    AWS Systems Manager Parameter Store fails to meet the requirement for automatic secret rotation every 90 days, as it does not natively provide this functionality for database credentials or API keys. While it effectively separates secrets from code and offers central management, making it a suitable choice for storing static configuration parameters or secrets that do not require lifecycle management, it lacks the built-in automated rotation mechanisms essential for this compliance policy.

    When this WOULD be correct

    A company needs to store configuration data (e.g., database URLs, AMI IDs) that does not require automatic rotation, and they want a free, scalable service integrated with EC2, ECS, and Lambda for parameter management.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CLF-C02 exam frequently reuses these exact scenarios with slightly different constraints.

AWS Secrets ManagerCorrect answer

Why this is correct

AWS Secrets Manager is purpose-built for storing, managing, and automatically rotating secrets such as database credentials and API keys. It integrates with Lambda to perform rotation on a schedule and with RDS for automatic credential updates, meeting the compliance requirements.

AWS Key Management Service (AWS KMS)Wrong answer — click to see why

Why this is wrong here

AWS KMS is a key management service for creating and controlling encryption keys, not for storing secrets like database credentials or API keys. It does not provide automatic rotation of secrets or a centralized secret store.

★ When this WOULD be the correct answer

A company needs to encrypt data at rest in Amazon S3 using customer-managed keys with automatic annual rotation. AWS KMS would be the correct service for managing the encryption keys.

Why candidates choose this

Candidates may confuse 'managing secrets' with 'managing encryption keys,' assuming KMS can store secrets because it handles keys and encryption.

AWS CloudHSMWrong answer — click to see why

Why this is wrong here

AWS CloudHSM provides hardware security modules for cryptographic key storage but does not offer automatic secret rotation or centralized management of application secrets like database credentials and API keys.

★ When this WOULD be the correct answer

A company needs to generate and store cryptographic keys in a dedicated, FIPS 140-2 Level 3 validated hardware security module (HSM) for compliance, and does not require automatic rotation of application secrets.

Why candidates choose this

Candidates may confuse CloudHSM's key storage capabilities with secret management, assuming it can handle credentials and API keys similarly to Secrets Manager.

AWS Systems Manager Parameter StoreWrong answer — click to see why

Why this is wrong here

AWS Systems Manager Parameter Store does not support automatic rotation of secrets; it requires custom solutions (e.g., Lambda) to rotate secrets, whereas the compliance policy mandates automatic rotation every 90 days.

★ When this WOULD be the correct answer

A company needs to store configuration data (e.g., database URLs, AMI IDs) that does not require automatic rotation, and they want a free, scalable service integrated with EC2, ECS, and Lambda for parameter management.

Why candidates choose this

Candidates may confuse Parameter Store with Secrets Manager because both can store secrets, but they overlook the automatic rotation requirement, which is a key differentiator in this question.

Analysis generated from the official CLF-C02blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

3 more ways this is tested on CLF-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company runs a web application on Amazon EC2 instances behind an Application Load Balancer. The application connects to an Amazon RDS for MySQL database. The database password is currently hardcoded in the application configuration file, and the security team is concerned about the risk of exposure. The company wants to remove the hardcoded credential and instead have the application retrieve the database password securely at runtime. Additionally, the security team requires that the password be automatically rotated every 90 days without any manual intervention or custom scripting. Which AWS service should the company use to meet these requirements?

medium
  • A.AWS Systems Manager Parameter Store (SecureString parameters)
  • B.AWS Key Management Service (AWS KMS)
  • C.AWS Secrets Manager
  • D.AWS Identity and Access Management (IAM) roles for Amazon EC2

Why C: AWS Secrets Manager is the correct choice because it is purpose-built for securely storing, retrieving, and automatically rotating database credentials (including RDS for MySQL) without custom code. It supports native, automatic rotation of secrets every 90 days via a built-in Lambda rotation function, meeting the security team's requirement for zero manual intervention. Unlike Parameter Store, Secrets Manager provides automatic rotation out of the box, which is the key differentiator here.

Variation 2. A company runs a web application that connects to an Amazon RDS for MySQL database. The security policy requires that the database password be rotated every 30 days. The development team wants a fully managed solution that automatically rotates the password, handles the update in RDS, and provides the application with the latest credentials without any code changes. The application should also continue to work during the rotation process. Which AWS service should the company use to meet these requirements?

medium
  • A.AWS Secrets Manager
  • B.AWS Systems Manager Parameter Store
  • C.AWS Key Management Service (AWS KMS)
  • D.AWS Identity and Access Management (IAM)

Why A: AWS Secrets Manager is the correct choice because it provides a fully managed service for automatic password rotation every 30 days, directly integrates with Amazon RDS for MySQL to update the database credentials, and supplies the latest credentials to the application via the Secrets Manager API without requiring any code changes. The rotation process is designed to ensure application availability by using a staged rotation strategy (e.g., creating a new credential while the old one remains valid) so the application continues to work during the rotation.

Variation 3. A company uses an Amazon RDS for PostgreSQL database for its production application. The security policy requires that database passwords be rotated automatically every 90 days. The database credentials are currently stored in a configuration file on an Amazon EC2 instance. The company wants a fully managed AWS service that can securely store the credentials, automatically rotate them on a schedule, and update the RDS instance without requiring code changes to the application. Which AWS service should the company use to meet these requirements?

medium
  • A.AWS Secrets Manager
  • B.AWS Systems Manager Parameter Store
  • C.AWS Key Management Service (KMS)
  • D.AWS Certificate Manager (ACM)

Why A: AWS Secrets Manager is the correct choice because it is a fully managed service designed specifically to securely store database credentials, automatically rotate them on a defined schedule (e.g., every 90 days), and natively integrate with Amazon RDS to update the password without requiring any application code changes. The application can retrieve the current credentials at runtime using the Secrets Manager API, eliminating the need for hardcoded or file-based credentials.

Last reviewed: Jun 11, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.