Courseiva
Security →mediumMultiple Choice

DVA-C02 Security Practice Question

A developer is building a serverless application using AWS Lambda and needs to securely store database credentials. Which AWS service should be used to store and retrieve the credentials?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Secrets Manager

AWS Secrets Manager (option B) is the correct choice because it is purpose-built to store, rotate, and retrieve secrets such as database credentials via API calls, and Lambda functions can fetch them at runtime using the AWS SDK with fine-grained IAM permissions. It also natively supports automatic rotation of credentials for supported databases like Amazon RDS, MySQL, and PostgreSQL, which reduces the risk of long-lived static credentials. AWS CloudFormation (A) is an infrastructure-as-code service for provisioning resources, not for storing secrets. AWS Systems Manager Parameter Store (C) can hold parameters including SecureString values, but it lacks built-in secret rotation and is less tailored to credential lifecycle management. AWS KMS (D) is an encryption key management service that encrypts data but does not itself store or serve database credentials.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS CloudFormation

    Why it's wrong here

    AWS CloudFormation is an Infrastructure as Code (IaC) service used for provisioning and managing AWS resources through declarative templates. It is not designed to securely store or manage sensitive application secrets like API keys or database credentials. While CloudFormation can define resources that utilize secrets, it does not act as a secret store itself, and embedding secrets directly into templates is a significant security anti-pattern, exposing them in plain text or easily retrievable parameters.

  • ✓

    AWS Secrets Manager

    Why this is correct

    AWS Secrets Manager is purpose-built for securely storing, managing, and retrieving sensitive information such as database credentials, API keys, and other application secrets throughout their lifecycle. It offers robust features like automatic rotation of secrets, fine-grained access control through IAM, and integration with other AWS services for easy secret injection into applications. Its ability to automatically rotate secrets without requiring application code changes is a key advantage for enhancing security posture and reducing operational overhead, making it the ideal choice for dynamic secret management.

  • ✗

    AWS Systems Manager Parameter Store

    Why it's wrong here

    AWS Systems Manager Parameter Store, a capability of AWS Systems Manager, can store configuration data and secrets, including encrypted parameters using AWS KMS. However, its primary design is for configuration management, not dynamic secret lifecycle management. While it can store secrets, it lacks native, automatic rotation capabilities, which is a critical security feature for sensitive credentials. Implementing secret rotation with Parameter Store would require custom Lambda functions or other external automation, adding significant complexity and operational burden.

  • ✗

    AWS Key Management Service (KMS)

    Why it's wrong here

    AWS Key Management Service (KMS) is a managed service that makes it easy to create and control encryption keys used to encrypt data across various AWS services. It provides cryptographic operations like encryption, decryption, and re-encryption, but it does not directly store the actual sensitive data or application secrets themselves. KMS is foundational for encrypting secrets *stored* in other services like Secrets Manager or Parameter Store, ensuring their confidentiality, but it is not a secret storage solution on its own; its role is to protect the keys, not the secrets.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.