Courseiva
Security and Compliance →mediumMultiple Choice

CLF-C02 Security and Compliance Practice Question

A company needs to store their application's database connection strings and automatically rotate them every 30 days. Which AWS service handles secret storage with automatic rotation built in?

⚠ Common exam trap

Many exam-takers confuse AWS Systems Manager Parameter Store (which can store secrets but lacks automatic rotation) with AWS Secrets Manager, leading them to choose Parameter Store when the question explicitly requires built-in rotation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Secrets Manager

AWS Secrets Manager is the correct service because it is specifically designed to securely store secrets such as database connection strings, API keys, and passwords, and it provides built-in automatic rotation of secrets at a configurable interval (e.g., every 30 days) using AWS Lambda. This eliminates the need for custom rotation logic and integrates natively with supported databases like Amazon RDS, Redshift, and DocumentDB.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Systems Manager Parameter Store

    Why it's wrong here

    AWS Systems Manager Parameter Store can securely store secrets as SecureString parameters, but it offers no native automatic rotation for database credentials. Rotation would require custom automation using AWS Lambda and manual version tracking. Secrets Manager is purpose-built for this, offering scheduled rotation, versioning, and direct RDS integration that Parameter Store lacks.

  • ✗

    Amazon S3 with encryption

    Why it's wrong here

    Amazon S3 with encryption is an object storage service, not a secrets manager. Storing credentials in S3 requires you to manage S3 bucket policies, encryption keys, and lifecycle configurations, and you must build a custom rotation process for any database passwords. S3 also lacks per-secret fine-grained access control and versioning designed for secrets, making it an inappropriate and insecure choice for dynamic credentials.

  • ✓

    AWS Secrets Manager

    Why this is correct

    AWS Secrets Manager is a purpose-built service for storing database credentials, API keys, and other secrets. It encrypts them with KMS, supports automatic rotation on a configurable schedule, and includes native integration with Amazon RDS to rotate credentials without application downtime. Versioning ensures applications always retrieve the latest secret, and IAM policies provide fine-grained access control.

  • ✗

    AWS KMS

    Why it's wrong here

    AWS KMS is a key management service that creates and controls customer master keys used for encrypting data, not for storing application-level secrets. It cannot rotate database credentials or other application secrets, and it does not provide a retrieval API for secret values. While Secrets Manager uses KMS to encrypt secrets at rest, KMS itself lacks the management and rotation capabilities needed for dynamic credentials.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every CLF-C02 question from scratch — 993 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.