DVA-C02 Security Practice Question
A company needs to store application secrets such as database passwords and API keys. The secrets must be automatically rotated every 30 days. Which THREE AWS services or features can be used together to meet this requirement? (Choose THREE.)
⚠ Common exam trap
It's easy for candidates to confuse AWS Systems Manager Parameter Store with Secrets Manager, but Parameter Store lacks native automatic rotation, making it unsuitable for this requirement without additional custom infrastructure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Lambda to implement the rotation function
AWS Lambda is correct because it can be used as a custom rotation function for AWS Secrets Manager. Secrets Manager natively supports automatic rotation using a Lambda function that updates the secret value in both the service and the database or third-party service. This allows the company to meet the 30-day rotation requirement by scheduling the Lambda function via a CloudWatch Events rule or Secrets Manager's built-in rotation schedule.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS Lambda to implement the rotation function
Why this is correct
AWS Lambda functions are essential for implementing the automatic rotation of secrets managed by AWS Secrets Manager. Secrets Manager invokes a pre-configured Lambda function on a scheduled basis to programmatically change the credentials in the target database or service. This function handles the logic for creating new credentials, updating the secret in Secrets Manager, and then deprecating the old credentials, ensuring secure and automated secret lifecycle management without manual intervention.
- ✗
AWS CloudHSM
Why it's wrong here
AWS CloudHSM provides dedicated hardware security modules (HSMs) in the AWS cloud, primarily used for cryptographic operations and secure key storage where FIPS 140-2 Level 3 compliance is required. While CloudHSM can store cryptographic keys, it is not designed to directly store application secrets like database credentials or to automate their rotation. Its purpose is to provide a highly secure, tamper-resistant environment for cryptographic keys, not a secrets management service.
- ✗
AWS Systems Manager Parameter Store
Why it's wrong here
AWS Systems Manager Parameter Store allows for secure storage of configuration data and secrets, offering hierarchical storage and integration with other AWS services. However, a critical limitation for this scenario is its lack of built-in automatic secret rotation capabilities. While it can store sensitive parameters encrypted with KMS, it does not provide the automated lifecycle management, including scheduled credential changes, that a dedicated secrets manager offers.
- ✓
AWS Secrets Manager
Why this is correct
AWS Secrets Manager is a fully managed service specifically designed to store, retrieve, and automatically rotate database credentials, API keys, and other secrets throughout their lifecycle. It integrates seamlessly with various AWS services and on-premises applications, providing secure access to secrets while minimizing the need for hardcoding sensitive information. Its primary advantage is the robust support for automated secret rotation, which significantly enhances security posture by regularly changing credentials.
- ✓
AWS KMS to encrypt the secrets
Why this is correct
AWS Key Management Service (KMS) is fundamental for securing secrets stored in AWS Secrets Manager. Secrets Manager leverages KMS customer master keys (CMKs) to encrypt the secret value at rest, ensuring that sensitive data like database credentials remains protected. When a secret is retrieved, Secrets Manager decrypts it using the associated KMS key, providing a robust encryption layer. This integration is crucial for maintaining data confidentiality and meeting compliance requirements.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
This DVA-C02 question is part of Courseiva's 1,135-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.