DEA-C01 Data Security and Governance Practice Question
A data engineer needs to securely store database credentials for an RDS instance. Which TWO AWS services can be used?
⚠ Common exam trap
DEA-C01 often tests the confusion between KMS (encryption keys) and Secrets Manager/Parameter Store (credential storage), and between IAM (permissions) and actual secret storage services.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Secrets Manager
AWS Secrets Manager (B) is correct because it is purpose-built to store, rotate, and retrieve secrets such as RDS database credentials, and it natively integrates with RDS for automatic credential rotation. AWS Systems Manager Parameter Store (E) is also correct because it can store database credentials as SecureString parameters, which are encrypted with AWS KMS, allowing the data engineer to retrieve them securely at runtime. AWS KMS (A) only provides encryption keys and cryptographic operations; it does not itself store credentials or secrets. AWS IAM (C) manages identities, roles, and permissions, not secret values. AWS CloudFormation (D) is an infrastructure-as-code provisioning service and is not designed to store or retrieve database credentials.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS KMS
Why it's wrong here
KMS creates and manages encryption keys but does not store credentials; it encrypts data other services hold. It is tempting because RDS encryption and Secrets Manager both rely on KMS keys, yet the requirement is credential storage, which Secrets Manager or Parameter Store provides directly.
- ✓
AWS Secrets Manager
Why this is correct
AWS Secrets Manager stores and rotates RDS credentials natively, with built-in rotation via Lambda and fine-grained IAM and KMS encryption. It satisfies the requirement to securely store database credentials rather than embedding them in code or configuration files.
- ✗
AWS IAM
Why it's wrong here
IAM manages identities, roles and permissions, not secret values; it cannot hold a database password. It is tempting because IAM authentication lets RDS verify identities without passwords, which suits token-based access, but the scenario requires storing credentials, so Secrets Manager or Parameter Store is needed.
- ✗
AWS CloudFormation
Why it's wrong here
CloudFormation provisions infrastructure as code and can reference secrets, but it does not itself store credentials securely. It is tempting because templates often pass database passwords as parameters, yet Secrets Manager or Systems Manager Parameter Store is what actually holds them encrypted.
- ✓
AWS Systems Manager Parameter Store
Why this is correct
AWS Systems Manager Parameter Store holds credentials as SecureString parameters encrypted with KMS, letting Glue and applications retrieve them via IAM-scoped references. It satisfies the secure-storage requirement, though rotation is manual rather than the automatic rotation Secrets Manager provides.
Go deeper
Related to this question
About these practice questions
This DEA-C01 question is part of Courseiva's 1,321-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.