Courseiva
Security →mediumMultiple Select

DVA-C02 Security Practice Question

A company needs to store application secrets such as database passwords and API keys. The secrets must be automatically rotated every 30 days. Which THREE AWS services or features can be used together to meet this requirement? (Choose THREE.)

⚠ Common exam trap

It's easy for candidates to confuse AWS Systems Manager Parameter Store with Secrets Manager, but Parameter Store lacks native automatic rotation, making it unsuitable for this requirement without additional custom infrastructure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Lambda to implement the rotation function

AWS Lambda is correct because it can be used as a custom rotation function for AWS Secrets Manager. Secrets Manager natively supports automatic rotation using a Lambda function that updates the secret value in both the service and the database or third-party service. This allows the company to meet the 30-day rotation requirement by scheduling the Lambda function via a CloudWatch Events rule or Secrets Manager's built-in rotation schedule.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    AWS Lambda to implement the rotation function

    Why this is correct

    AWS Lambda functions are essential for implementing the automatic rotation of secrets managed by AWS Secrets Manager. Secrets Manager invokes a pre-configured Lambda function on a scheduled basis to programmatically change the credentials in the target database or service. This function handles the logic for creating new credentials, updating the secret in Secrets Manager, and then deprecating the old credentials, ensuring secure and automated secret lifecycle management without manual intervention.

  • ✗

    AWS CloudHSM

    Why it's wrong here

    AWS CloudHSM provides dedicated hardware security modules (HSMs) in the AWS cloud, primarily used for cryptographic operations and secure key storage where FIPS 140-2 Level 3 compliance is required. While CloudHSM can store cryptographic keys, it is not designed to directly store application secrets like database credentials or to automate their rotation. Its purpose is to provide a highly secure, tamper-resistant environment for cryptographic keys, not a secrets management service.

  • ✗

    AWS Systems Manager Parameter Store

    Why it's wrong here

    AWS Systems Manager Parameter Store allows for secure storage of configuration data and secrets, offering hierarchical storage and integration with other AWS services. However, a critical limitation for this scenario is its lack of built-in automatic secret rotation capabilities. While it can store sensitive parameters encrypted with KMS, it does not provide the automated lifecycle management, including scheduled credential changes, that a dedicated secrets manager offers.

  • ✓

    AWS Secrets Manager

    Why this is correct

    AWS Secrets Manager is a fully managed service specifically designed to store, retrieve, and automatically rotate database credentials, API keys, and other secrets throughout their lifecycle. It integrates seamlessly with various AWS services and on-premises applications, providing secure access to secrets while minimizing the need for hardcoding sensitive information. Its primary advantage is the robust support for automated secret rotation, which significantly enhances security posture by regularly changing credentials.

  • ✓

    AWS KMS to encrypt the secrets

    Why this is correct

    AWS Key Management Service (KMS) is fundamental for securing secrets stored in AWS Secrets Manager. Secrets Manager leverages KMS customer master keys (CMKs) to encrypt the secret value at rest, ensuring that sensitive data like database credentials remains protected. When a secret is retrieved, Secrets Manager decrypts it using the associated KMS key, providing a robust encryption layer. This integration is crucial for maintaining data confidentiality and meeting compliance requirements.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

This DVA-C02 question is part of Courseiva's 1,135-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.