CLF-C02 Security and Compliance Practice Question
A company needs to store their application's database connection strings and automatically rotate them every 30 days. Which AWS service handles secret storage with automatic rotation built in?
⚠ Common exam trap
Many exam-takers confuse AWS Systems Manager Parameter Store (which can store secrets but lacks automatic rotation) with AWS Secrets Manager, leading them to choose Parameter Store when the question explicitly requires built-in rotation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Secrets Manager
AWS Secrets Manager is the correct service because it is specifically designed to securely store secrets such as database connection strings, API keys, and passwords, and it provides built-in automatic rotation of secrets at a configurable interval (e.g., every 30 days) using AWS Lambda. This eliminates the need for custom rotation logic and integrates natively with supported databases like Amazon RDS, Redshift, and DocumentDB.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Systems Manager Parameter Store
Why it's wrong here
AWS Systems Manager Parameter Store can securely store secrets as SecureString parameters, but it offers no native automatic rotation for database credentials. Rotation would require custom automation using AWS Lambda and manual version tracking. Secrets Manager is purpose-built for this, offering scheduled rotation, versioning, and direct RDS integration that Parameter Store lacks.
- ✗
Amazon S3 with encryption
Why it's wrong here
Amazon S3 with encryption is an object storage service, not a secrets manager. Storing credentials in S3 requires you to manage S3 bucket policies, encryption keys, and lifecycle configurations, and you must build a custom rotation process for any database passwords. S3 also lacks per-secret fine-grained access control and versioning designed for secrets, making it an inappropriate and insecure choice for dynamic credentials.
- ✓
AWS Secrets Manager
Why this is correct
AWS Secrets Manager is a purpose-built service for storing database credentials, API keys, and other secrets. It encrypts them with KMS, supports automatic rotation on a configurable schedule, and includes native integration with Amazon RDS to rotate credentials without application downtime. Versioning ensures applications always retrieve the latest secret, and IAM policies provide fine-grained access control.
- ✗
AWS KMS
Why it's wrong here
AWS KMS is a key management service that creates and controls customer master keys used for encrypting data, not for storing application-level secrets. It cannot rotate database credentials or other application secrets, and it does not provide a retrieval API for secret values. While Secrets Manager uses KMS to encrypt secrets at rest, KMS itself lacks the management and rotation capabilities needed for dynamic credentials.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every CLF-C02 question from scratch — 993 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.