DVA-C02 Security Practice Question
A developer is storing secrets such as database passwords. Which TWO AWS services can be used to securely store and retrieve secrets?
⚠ Common exam trap
DVA-C02 often tests the distinction between services that store secrets versus those that manage access or keys, causing candidates to confuse IAM or CloudHSM with secret storage solutions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Systems Manager Parameter Store
AWS Systems Manager Parameter Store (B) is correct because it can store secrets as SecureString parameters, which are encrypted with AWS KMS and can be retrieved programmatically by applications via the SSM API, making it a valid service for storing and retrieving database passwords. AWS Secrets Manager (D) is correct because it is purpose-built for storing, retrieving, and rotating secrets such as database credentials, using KMS encryption and APIs like GetSecretValue. AWS CloudHSM (A) is not correct here because it provides dedicated hardware security modules for cryptographic key operations, not a managed secret storage and retrieval service. AWS Identity and Access Management (C) manages identities, permissions, and policies rather than storing secret values. Amazon S3 (E) is object storage and, while it can be encrypted, it is not designed as a secrets management service for securely storing and retrieving credentials.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS CloudHSM
Why it's wrong here
AWS CloudHSM is a hardware security module (HSM) that provides tamper-resistant cryptographic key storage and cryptographic operations, not a service for storing arbitrary secrets like database passwords. To use it for secrets, you would need to design custom encryption/decryption logic and manage the application integration yourself. It is meant for regulatory compliance around key management, not as a general-purpose secret store.
- ✓
AWS Systems Manager Parameter Store
Why this is correct
AWS Systems Manager Parameter Store is a secure, hierarchical service for storing configuration data and secrets, including database passwords, as String, StringList, or SecureString parameters. SecureString parameters are encrypted with AWS KMS and can be retrieved via the AWS SDK, CLI, or directly from EC2 and Lambda, with IAM policies controlling access. It is a low-cost, no-extra-fee option (beyond KMS) and supports versioning, making it a lightweight and practical choice when you don't need built-in automatic rotation.
- ✗
AWS Identity and Access Management (IAM)
Why it's wrong here
AWS Identity and Access Management (IAM) is designed to manage identities, users, groups, roles, and permissions, not to store application secrets such as database passwords. IAM does store certain credentials (user login passwords and access keys), but it has no API for storing free-form key-value pairs or arbitrary secret values. Therefore, it cannot be used as a secret store for your application's database credentials, and trying to use IAM for this purpose is conceptually incorrect.
- ✓
AWS Secrets Manager
Why this is correct
AWS Secrets Manager is a purpose-built service for managing secrets like database credentials, offering built-in automatic rotation via AWS Lambda, fine-grained IAM access control, and native integration with services like RDS, Redshift, and DocumentDB. It stores secrets encrypted by KMS and provides APIs specifically designed for secure retrieval at runtime. It is a correct choice when you need rotation, auditability, and cross-account secret sharing, although it incurs a monthly charge per secret, so for simple static secrets without rotation, Parameter Store may be more cost-effective.
- ✗
Amazon S3
Why it's wrong here
Amazon S3 is object storage for files, media, backups, and other unstructured data, not a service designed for secrets management. While you could upload a file containing encrypted secrets, you would be responsible for managing encryption keys, access policies, versioning, and rotation yourself, and there is no native semantic for retrieving a single secret value as a parameter. Storing plaintext database passwords in S3 is a common anti-pattern that violates security best practices, so S3 is not a suitable or secure secret store.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This DVA-C02 question is part of Courseiva's 1,135-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.