Courseiva
Security →easyMultiple Select

DVA-C02 Security Practice Question

A developer is tasked with securing a legacy application that stores secrets in environment variables. Which THREE AWS services can be used to improve the security posture?

⚠ Common exam trap

DVA-C02 often tests the distinction between secret storage services and certificate/HSM services — candidates pick ACM or CloudHSM thinking 'security,' but those do not store application secrets.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Key Management Service (KMS)

AWS Key Management Service (KMS) (A) is correct because it provides managed encryption keys that can be used to encrypt secrets at rest, and it integrates with services like Secrets Manager and Parameter Store to protect the underlying data with customer master keys (CMKs). AWS Systems Manager Parameter Store (D) is correct because it offers a centralized, secure store for configuration data and secrets, supports SecureString parameters encrypted via KMS, and can be referenced by applications instead of hardcoding values in environment variables. AWS Secrets Manager (E) is correct because it is purpose-built for storing, rotating, and retrieving secrets such as database credentials and API keys, with native KMS encryption and fine-grained IAM access control. AWS Certificate Manager (B) is not correct because it manages and provisions TLS/SSL certificates for services like ELB and CloudFront, not application secrets. AWS CloudHSM (C) is not correct because it provides dedicated hardware security modules for cryptographic operations and key storage, but it is not a secrets management service for replacing environment-variable-stored secrets.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    AWS Key Management Service (KMS)

    Why this is correct

    AWS KMS is the correct answer because it provides the encryption key management that secures secrets at rest. KMS creates and protects Customer Master Keys (CMKs) that can encrypt data keys via envelope encryption, and both Systems Manager Parameter Store and Secrets Manager rely on KMS to encrypt their stored secret values. While KMS itself is not a secrets repository, it is the foundational service that makes secure secret storage possible. For this legacy application, using KMS to encrypt secrets either directly or through integration with other AWS services satisfies the security requirement.

  • ✗

    AWS Certificate Manager

    Why it's wrong here

    AWS Certificate Manager is incorrect because it exclusively manages SSL/TLS certificates and their associated private keys for network encryption (in transit), not application secrets such as database passwords or API keys. ACM automates certificate issuance, renewal, and deployment to AWS resources like ALBs and CloudFront, but it does not provide a general-purpose interface to store, retrieve, or rotate arbitrary secret values. The certificates ACM issues are meant to be publicly presented, so they are not considered private secrets. Therefore, ACM does not address the developer's need to secure secrets for the legacy application.

  • ✗

    AWS CloudHSM

    Why it's wrong here

    AWS CloudHSM is incorrect because it offers hardware security modules that provide FIPS 140-2 validated, tamper-resistant hardware for cryptographic key operations, but it is designed for regulated workloads that require dedicated, customer-controlled HSM appliances. Using CloudHSM for simple secret storage is an operational overkill because you must manage the HSM cluster, partitions, and scaling yourself, whereas AWS KMS offers a fully managed equivalent. Additionally, CloudHSM does not natively store application secrets like passwords; it only protects the cryptographic keys used for encryption. For this use case, the fully managed and lower-complexity KMS service is the appropriate choice.

  • ✓

    AWS Systems Manager Parameter Store

    Why this is correct

    Systems Manager Parameter Store is a correct option because it provides a secure, hierarchical store for configuration data and secrets, supporting plaintext and encrypted SecureString parameters. It integrates with AWS KMS to encrypt parameter values, making it suitable for storing database credentials, API keys, and other secrets with fine-grained AWS IAM access control. Parameter Store is a cost-effective and simple solution, especially for legacy applications, but it lacks advanced features like automatic secret rotation, which is available in Secrets Manager. Nonetheless, it enables the developer to securely store and retrieve secrets for the legacy application.

  • ✓

    AWS Secrets Manager

    Why this is correct

    AWS Secrets Manager is a correct option because it is a purpose-built service for centralizing and managing secrets throughout their entire lifecycle, including database credentials, API keys, and other sensitive values. It automatically encrypts secrets using KMS, enforces resource-based and IAM policies, and supports built-in rotation via Lambda to regularly change credentials—a critical capability for legacy applications with hardcoded secrets. Secrets Manager also enables fine-grained access control and secret versioning. For securing a legacy application, Secrets Manager is the recommended, fully managed secrets management solution.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.