Courseiva
Security →mediumMultiple Choice

DVA-C02 Security Practice Question

A company is using AWS CodePipeline to deploy a web application. The pipeline must securely store and use database credentials. Which AWS service should the developer use to store the credentials and retrieve them during deployment?

⚠ Common exam trap

DVA-C02 often tests the Secrets Manager vs. Parameter Store distinction — candidates pick Parameter Store SecureString for credentials, missing that Secrets Manager is the AWS-recommended service when rotation and credential lifecycle management are required.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Secrets Manager.

AWS Secrets Manager is purpose-built for storing, rotating, and retrieving sensitive credentials like database passwords. It integrates natively with CodePipeline/CodeBuild via the AWS CLI or SDK, supports automatic rotation via Lambda, and provides fine-grained IAM access control and encryption with KMS. This makes it the correct choice for securely storing and retrieving database credentials during deployment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    IAM role attached to the CodePipeline service role.

    Why it's wrong here

    An IAM role defines a set of permissions that an AWS service or user can assume to interact with other AWS services. While CodePipeline utilizes an IAM service role to perform actions like deploying resources, this role is a mechanism for authorization and access control, not a secure storage solution for sensitive data. Storing database passwords directly within an IAM role's configuration or policy document would be a severe security anti-pattern, exposing the secret to anyone with permissions to view the role.

  • ✓

    AWS Secrets Manager.

    Why this is correct

    AWS Secrets Manager is purpose-built for securely storing, managing, and rotating sensitive credentials such as database passwords, API keys, and other secrets. It integrates directly with various AWS services, including CodePipeline, and offers automatic rotation capabilities for many database types, enhancing security by regularly changing credentials without manual intervention. This service provides robust encryption at rest and in transit, fine-grained access control, and auditability through AWS CloudTrail, making it the most appropriate choice for this use case.

  • ✗

    AWS Systems Manager Parameter Store with a SecureString parameter.

    Why it's wrong here

    AWS Systems Manager Parameter Store, particularly with SecureString parameters, can indeed store sensitive data encrypted using KMS keys. While it's a viable option for general configuration and some secrets, it lacks the advanced features specifically designed for database credentials that Secrets Manager provides. Parameter Store does not natively support automatic rotation of database credentials, which is a critical security best practice for long-lived secrets, nor does it offer the same level of integration with database services for credential management.

  • ✗

    Amazon DynamoDB with server-side encryption.

    Why it's wrong here

    Amazon DynamoDB is a fast, flexible NoSQL database service designed for applications requiring consistent, single-digit millisecond latency at any scale. While it supports server-side encryption to protect data at rest, it is fundamentally a data storage solution for application data, not a dedicated service for managing and rotating secrets like database credentials. Using DynamoDB for this purpose would require building a custom secrets management and rotation mechanism, which would be complex, error-prone, and less secure than leveraging a specialized service.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

Courseiva writes every DVA-C02 question from scratch — 1,135 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.