Courseiva
Security →mediumMultiple Select

DVA-C02 Security Practice Question

A company wants to securely store database credentials for a Lambda function. The credentials must be automatically rotated. Which TWO services should be used together?

⚠ Common exam trap

A common mix-up: candidates confuse AWS Systems Manager Parameter Store with Secrets Manager because both can store secrets, but Parameter Store lacks automatic rotation, which is explicitly required in the question.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Secrets Manager

AWS Secrets Manager is the correct service because it is purpose-built for securely storing, retrieving, and automatically rotating database credentials and other secrets. It integrates natively with AWS Lambda and supports automatic rotation via a built-in rotation function or a custom Lambda function, meeting the requirement for automated credential rotation without manual intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS KMS

    Why it's wrong here

    AWS Key Management Service (KMS) is primarily designed for creating and managing cryptographic keys used to encrypt data. While KMS can encrypt database credentials, it does not offer a direct mechanism for storing the credentials themselves or for implementing automatic rotation of these secrets. It serves as an encryption primitive, not a comprehensive secret management solution capable of handling the lifecycle of credentials. Therefore, it is not suitable for the secure storage and rotation requirement.

  • ✓

    AWS Secrets Manager

    Why this is correct

    AWS Secrets Manager is a dedicated service for securely storing and managing secrets, including database credentials. It provides robust features for automatic rotation of secrets, which is crucial for enhancing security by regularly changing credentials without manual intervention. Furthermore, it integrates seamlessly with various AWS databases and services, simplifying the process of retrieving and using secrets in applications, making it the ideal solution.

  • ✗

    AWS CloudHSM

    Why it's wrong here

    AWS CloudHSM provides dedicated hardware security modules (HSMs) for cryptographic operations and secure key storage, meeting stringent compliance requirements. While it offers a highly secure environment for cryptographic keys, it is a low-level service that does not natively support the storage of general database credentials or offer built-in functionality for automatic secret rotation. Its primary focus is on cryptographic key management, not comprehensive secret lifecycle management, making it an unsuitable choice for this purpose.

  • ✓

    AWS Lambda

    Why this is correct

    AWS Lambda is a serverless compute service that can execute custom code in response to events. For secret management, Lambda functions can be leveraged to implement highly customized rotation logic for database credentials, particularly for databases or services not natively supported by AWS Secrets Manager's built-in rotators. This allows developers to programmatically connect to a database, change the credentials, and then update the corresponding secret store, making it a viable option for custom rotation.

  • ✗

    AWS Systems Manager Parameter Store

    Why it's wrong here

    AWS Systems Manager Parameter Store offers secure, hierarchical storage for configuration data and secrets, including database credentials stored as SecureString parameters. While it provides encryption using KMS and can be integrated into application deployments, it fundamentally lacks built-in automatic rotation capabilities for these secrets. Manual intervention would be required to update credentials, which is not ideal for maintaining a strong security posture over time, thus making it an incorrect choice for automatic rotation.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on DVA-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company wants to store database credentials securely and rotate them automatically on a schedule. The credentials are used by an AWS Lambda function to access an Amazon RDS instance. Which AWS service should the developer use to meet these requirements?

medium
  • ✓ A.AWS Secrets Manager
  • B.AWS Systems Manager Parameter Store
  • C.AWS Key Management Service (KMS)
  • D.AWS Certificate Manager (ACM)

Why A: AWS Secrets Manager is the correct choice because it is specifically designed to securely store, retrieve, and automatically rotate database credentials on a schedule. It natively supports automatic rotation for Amazon RDS databases (including MySQL, PostgreSQL, Oracle, SQL Server, and MariaDB) by integrating with Lambda to update the credentials in both Secrets Manager and the RDS instance. This meets the requirement for both secure storage and scheduled rotation without custom infrastructure.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.