DVA-C02 Security Practice Question
A developer is deploying an application with AWS CodeDeploy. The application needs to access a database password. Which service should be used to securely store and retrieve the password?
⚠ Common exam trap
DVA-C02 often tests whether candidates choose Parameter Store over Secrets Manager for database passwords; while Parameter Store can store secure strings, Secrets Manager is the correct answer when rotation and native integration are required.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Secrets Manager
AWS Secrets Manager is designed specifically for securely storing, rotating, and retrieving secrets such as database passwords, API keys, and tokens. It integrates natively with AWS services like RDS and provides fine-grained access control via IAM. CodeDeploy deployments can retrieve secrets at runtime using the Secrets Manager API or SDK.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Systems Manager Parameter Store
Why it's wrong here
AWS Systems Manager Parameter Store can securely store sensitive data using AWS Key Management Service (KMS) encryption, making it suitable for general configuration parameters and some secrets. However, it does not offer native, automatic secret rotation capabilities for database credentials or API keys, which is a critical security best practice for minimizing the impact of compromised secrets. Implementing rotation would require custom Lambda functions and additional operational overhead, making it less ideal for secrets requiring frequent, automated lifecycle management compared to a dedicated service.
- ✗
AWS CloudFormation template parameters
Why it's wrong here
AWS CloudFormation template parameters are designed for passing configuration values into a stack during deployment, not for securely storing sensitive information like database passwords or API keys. These parameters are typically visible in plain text within the CloudFormation console, API calls, or stack events, making them highly insecure for secrets. They lack the robust encryption, access controls, and lifecycle management features essential for protecting sensitive credentials throughout their operational lifespan.
- ✗
Amazon DynamoDB with encryption at rest
Why it's wrong here
Amazon DynamoDB, while a highly secure and scalable NoSQL database with encryption at rest, is not purpose-built for secrets management. It lacks the specialized features crucial for handling secrets, such as automatic rotation for various credential types, built-in secret generation, fine-grained access policies tailored for secret retrieval, and integration with application runtime environments for secure secret injection. Using DynamoDB for secrets would necessitate significant custom development to replicate the functionality offered by a dedicated secrets manager.
- ✓
AWS Secrets Manager
Why this is correct
AWS Secrets Manager is purpose-built for securely storing, managing, and retrieving secrets throughout their lifecycle, making it the optimal choice for applications. It natively supports automatic rotation for various types of credentials, including database passwords (e.g., RDS, Redshift, DocumentDB) and API keys, significantly enhancing security by regularly changing secrets without requiring application code changes. Furthermore, it provides fine-grained access control, auditing capabilities, and seamless integration with other AWS services like CodeDeploy and Lambda for secure secret injection and retrieval.
Go deeper
Related to this question
About these practice questions
One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.