DVA-C02 Security Practice Question
A company is designing a secure CI/CD pipeline using AWS CodePipeline and AWS CodeBuild. The pipeline must securely store and access sensitive parameters (e.g., API keys) used during the build. Which TWO services can be used to securely store and retrieve these parameters?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Systems Manager Parameter Store (SecureString)
AWS Systems Manager Parameter Store (SecureString) and AWS Secrets Manager are both designed to securely store secrets and can be accessed by CodeBuild via IAM roles.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS Systems Manager Parameter Store (SecureString)
Why this is correct
Systems Manager Parameter Store lets you store values as SecureString parameters encrypted under a KMS key, and CodeBuild buildspec files natively support pulling these into environment variables at build time via the parameter-store mapping, making it a valid secure retrieval mechanism.
- ✓
AWS Secrets Manager
Why this is correct
AWS Secrets Manager is purpose-built for credential storage, offering automatic rotation, fine-grained resource policies, and a secrets-manager mapping in the CodeBuild buildspec, making it a valid and often preferred option for highly sensitive values like database passwords or API keys.
- ✗
Amazon S3 with server-side encryption
Why it's wrong here
This is incorrect because S3 with server-side encryption only protects objects at rest within the bucket; it provides no native secrets lifecycle features such as rotation, fine-grained IAM condition scoping for secret access, or a direct CodeBuild buildspec integration, making it a poor fit compared to purpose-built secret stores.
- ✗
AWS Key Management Service (KMS) alone
Why it's wrong here
This is wrong because KMS by itself is strictly a key management and cryptographic operations service — it generates and manages the encryption keys used by Parameter Store or Secrets Manager, but it has no mechanism to store or serve the actual secret value to a build process.
- ✗
AWS CloudFormation parameter store
Why it's wrong here
This is incorrect because CloudFormation parameters exist to customize a stack's resources at deployment time and can even be flagged NoEcho to mask console display, but they are not a runtime secrets store that CodeBuild can query during a build, and NoEcho does not provide real encryption at rest.
Go deeper
Related to this question
About these practice questions
This DVA-C02 question is part of Courseiva's 1,135-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.