Courseiva

DVA-C02 Development with AWS Services Practice Question

A company is developing a microservices architecture using Amazon ECS with Fargate launch type. Each microservice needs to store sensitive configuration data such as database passwords. The company wants to avoid storing secrets in the application code or environment variables. What is the MOST secure and recommended approach?

⚠ Common exam trap

DVA-C02 often tests the misconception that environment variables in task definitions are secure — candidates pick option A because it is convenient, missing that task definition environment variables are visible in plaintext via the ECS API and console.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use AWS Systems Manager Parameter Store or AWS Secrets Manager to store and retrieve secrets.

AWS Systems Manager Parameter Store (SecureString) and AWS Secrets Manager are purpose-built services for storing and retrieving secrets securely, with encryption at rest via KMS, fine-grained IAM access control, and native integration with ECS/Fargate task definitions. Secrets Manager additionally supports automatic rotation. This is the AWS-recommended approach for injecting secrets into containerized workloads without hardcoding them.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Pass secrets as environment variables in the task definition.

    Why it's wrong here

    Passing secrets as environment variables is a significant security risk because these variables are not encrypted at rest within the task definition and can be easily exposed. They are often visible in process listings, application logs, or through container inspection tools, making them vulnerable to unauthorized access. This method also lacks built-in rotation capabilities and fine-grained access control.

  • ✗

    Store secrets in an encrypted S3 bucket and have the application download them at startup.

    Why it's wrong here

    Storing secrets in an encrypted S3 bucket introduces unnecessary complexity and potential exposure. While S3 provides encryption, the application would still need to be granted IAM permissions to access the bucket, and the credentials for this access would themselves become a new secret management problem. This approach requires custom code for retrieval and decryption, increasing the operational overhead and attack surface compared to dedicated secret management services.

  • ✓

    Use AWS Systems Manager Parameter Store or AWS Secrets Manager to store and retrieve secrets.

    Why this is correct

    AWS Systems Manager Parameter Store (specifically Secure String parameters) and AWS Secrets Manager are purpose-built services designed for the secure storage, retrieval, and rotation of sensitive information. They integrate natively with AWS Key Management Service (KMS) for encryption at rest and AWS Identity and Access Management (IAM) for fine-grained access control, providing a robust and compliant solution for managing secrets in a microservices architecture.

  • ✗

    Use an AWS Lambda function to generate secrets and store them in DynamoDB.

    Why it's wrong here

    Using an AWS Lambda function to generate secrets and store them in DynamoDB introduces significant architectural complexity and security challenges. DynamoDB, while encrypted at rest, lacks the native secret management features such as automatic rotation, versioning, and secure retrieval mechanisms that dedicated services provide. This custom solution would require extensive development, auditing, and maintenance to achieve a comparable security posture.

About these practice questions

One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.