DVA-C02 Security Practice Question
A company is using AWS CodePipeline to deploy a web application. The pipeline must securely store and use database credentials. Which AWS service should the developer use to store the credentials and retrieve them during deployment?
⚠ Common exam trap
DVA-C02 often tests the Secrets Manager vs. Parameter Store distinction — candidates pick Parameter Store SecureString for credentials, missing that Secrets Manager is the AWS-recommended service when rotation and credential lifecycle management are required.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Secrets Manager.
AWS Secrets Manager is purpose-built for storing, rotating, and retrieving sensitive credentials like database passwords. It integrates natively with CodePipeline/CodeBuild via the AWS CLI or SDK, supports automatic rotation via Lambda, and provides fine-grained IAM access control and encryption with KMS. This makes it the correct choice for securely storing and retrieving database credentials during deployment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
IAM role attached to the CodePipeline service role.
Why it's wrong here
An IAM role defines a set of permissions that an AWS service or user can assume to interact with other AWS services. While CodePipeline utilizes an IAM service role to perform actions like deploying resources, this role is a mechanism for authorization and access control, not a secure storage solution for sensitive data. Storing database passwords directly within an IAM role's configuration or policy document would be a severe security anti-pattern, exposing the secret to anyone with permissions to view the role.
- ✓
AWS Secrets Manager.
Why this is correct
AWS Secrets Manager is purpose-built for securely storing, managing, and rotating sensitive credentials such as database passwords, API keys, and other secrets. It integrates directly with various AWS services, including CodePipeline, and offers automatic rotation capabilities for many database types, enhancing security by regularly changing credentials without manual intervention. This service provides robust encryption at rest and in transit, fine-grained access control, and auditability through AWS CloudTrail, making it the most appropriate choice for this use case.
- ✗
AWS Systems Manager Parameter Store with a SecureString parameter.
Why it's wrong here
AWS Systems Manager Parameter Store, particularly with SecureString parameters, can indeed store sensitive data encrypted using KMS keys. While it's a viable option for general configuration and some secrets, it lacks the advanced features specifically designed for database credentials that Secrets Manager provides. Parameter Store does not natively support automatic rotation of database credentials, which is a critical security best practice for long-lived secrets, nor does it offer the same level of integration with database services for credential management.
- ✗
Amazon DynamoDB with server-side encryption.
Why it's wrong here
Amazon DynamoDB is a fast, flexible NoSQL database service designed for applications requiring consistent, single-digit millisecond latency at any scale. While it supports server-side encryption to protect data at rest, it is fundamentally a data storage solution for application data, not a dedicated service for managing and rotating secrets like database credentials. Using DynamoDB for this purpose would require building a custom secrets management and rotation mechanism, which would be complex, error-prone, and less secure than leveraging a specialized service.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DVA-C02 question from scratch — 1,135 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.