DVA-C02 Security Practice Question
A developer needs to encrypt secrets (database passwords) that are used by an application running on EC2. The application retrieves the secrets at startup. Which combination of services provides the MOST secure and manageable solution?
⚠ Common exam trap
DVA-C02 often tests secret management best practices; candidates may choose Parameter Store SecureString as it is also secure, but Secrets Manager is preferred for its automatic rotation and dedicated secret management features.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Store the secrets in AWS Secrets Manager and use an IAM role to access them.
Storing secrets in AWS Secrets Manager and using an IAM role to access them provides the most secure and manageable solution. Secrets Manager is designed for secret management, supports automatic rotation, and integrates with IAM for fine-grained access control. Using an IAM role for EC2 eliminates the need to embed credentials in the application, enhancing security.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Store the secrets in AWS Secrets Manager and use an IAM role to access them.
Why this is correct
Secrets Manager stores the database passwords centrally and supports native rotation, while the EC2 instance profile's IAM role grants retrieval permissions without embedding long-lived credentials. This removes hard-coded secrets and satisfies the secure, manageable requirement.
- ✗
Encrypt the secrets with AWS KMS and store them in an S3 bucket with a bucket policy.
Why it's wrong here
Storing encrypted secrets in S3 with a bucket policy lacks a native mechanism for the EC2 application to securely retrieve and decrypt them without embedding a long-term credential in the application code or instance metadata. The correct solution uses AWS Systems Manager Parameter Store or Secrets Manager with an IAM role attached to the EC2 instance, which grants temporary, scoped access at startup. This option is tempting because S3 with KMS encryption is a common pattern for static data at rest, and it would be correct for storing encrypted configuration files that are manually retrieved by an administrator rather than by an application at runtime.
- ✗
Store the secrets in AWS Systems Manager Parameter Store with a SecureString parameter.
Why it's wrong here
Parameter Store SecureString encrypts values with KMS but lacks native automatic rotation for database credentials, so rotation stays manual. Secrets Manager is the intended service because it rotates RDS and similar secrets on a schedule. Parameter Store suits plain configuration values and licence strings rather than rotating credentials.
- ✗
Hardcode the secrets in the application code and encrypt the code.
Why it's wrong here
Encrypting code leaves secrets recoverable by anyone who can decrypt or run it, and rotation demands a redeploy. Secrets Manager stores credentials outside the artefact and rotates them automatically. Hardcoding would only be defensible for non-sensitive, non-rotating constants in throwaway prototypes.
Go deeper
Related to this question
About these practice questions
One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.