DVA-C02 Development with AWS Services Practice Question
A developer is deploying an application using AWS Elastic Beanstalk. The application reads and writes data to an Amazon RDS database. The developer wants to ensure that database credentials are not stored in the application code or configuration files. What should the developer do?
⚠ Common exam trap
Candidates often choose Elastic Beanstalk environment properties (Option A) because it is a built-in feature of Elastic Beanstalk. However, AWS security best practices dictate using AWS Secrets Manager or Systems Manager Parameter Store (SecureString) for sensitive data like database credentials to ensure encryption at rest and support credential rotation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use AWS Secrets Manager to store the credentials and retrieve them in the application code.
AWS Secrets Manager is specifically designed to protect secrets (such as database credentials, API keys, and OAuth tokens) needed to access applications, services, and IT resources. It enables you to easily rotate, manage, and retrieve database credentials throughout their lifecycle. Storing credentials in Elastic Beanstalk environment properties (Option A) is a security risk because they are stored in plaintext within the environment configuration, can be exposed via the AWS Console/API to users with Beanstalk permissions, and do not support automatic rotation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Store the credentials as environment properties in the Elastic Beanstalk environment configuration.
Why it's wrong here
Elastic Beanstalk environment properties provide a secure and straightforward mechanism for injecting configuration, including credentials, into applications. These properties are stored securely by the Elastic Beanstalk service and are exposed as environment variables to the application instances at runtime. This approach keeps sensitive information out of the application's source code and version control, simplifying credential management and rotation while maintaining a clear separation of configuration from code.
- ✗
Encrypt the credentials and store them in an Amazon S3 bucket. Have the application download them at startup.
Why it's wrong here
Encrypting credentials and storing them in an Amazon S3 bucket introduces unnecessary complexity and potential security risks. The application would still require an IAM role with S3 read access, and it would need to embed decryption logic and a decryption key (or access to AWS KMS) within its code or environment. This method complicates key management, adds overhead for application startup, and creates additional attack surfaces compared to native environment configuration or dedicated secret management services.
- ✓
Use AWS Secrets Manager to store the credentials and retrieve them in the application code.
Why this is correct
Secrets Manager stores credentials securely and retrieves them via API calls, but the question requires that credentials are never stored in application code or configuration files. The correct approach uses IAM database authentication with RDS, eliminating static credentials entirely by granting the Elastic Beanstalk environment’s IAM role direct access to the database. Secrets Manager is tempting because it is designed for secure credential storage and rotation, and would be correct if the application needed static credentials that could not be eliminated, such as when RDS does not support IAM authentication.
- ✗
Store the credentials in a separate configuration file and include it in the application source bundle.
Why it's wrong here
Including credentials directly in a separate configuration file within the application source bundle is a significant security anti-pattern. This practice exposes sensitive information to anyone with access to the source code repository, including its history, and makes credential rotation cumbersome. It violates the principle of separating configuration from code and increases the risk of accidental exposure during development, deployment, or if the source bundle is compromised.
Go deeper
Related to this question
About these practice questions
One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.