Courseiva
Question 883 of 724
SecurityeasyMultiple ChoiceObjective-mapped

DVA-C02 Security Practice Question

A developer needs to securely store database credentials for a Lambda function. The credentials must be automatically rotated every 90 days. Which AWS service should be used?

⚠ Common exam trap

It's easy for candidates to confuse AWS Systems Manager Parameter Store (which can store secrets securely but lacks automatic rotation) with AWS Secrets Manager, leading them to choose Parameter Store when the question explicitly requires automatic rotation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

AWS Secrets Manager

AWS Secrets Manager is the correct service because it is designed specifically for securely storing, managing, and automatically rotating database credentials and other secrets. It supports built-in rotation with AWS Lambda, allowing you to set a custom rotation interval (e.g., 90 days) without custom infrastructure. Secrets Manager also integrates natively with Amazon RDS, Redshift, and DocumentDB for automatic credential rotation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • AWS Secrets Manager

    Why this is correct

    AWS Secrets Manager is the correct choice because it is purpose-built for securely storing, managing, and retrieving sensitive credentials like database passwords, API keys, and other secrets. A key feature is its ability to automatically rotate secrets, including integrating with databases to generate new credentials and update the database directly. This automation significantly enhances security by regularly changing credentials without manual intervention, reducing the risk of compromise and ensuring compliance with security best practices.

  • AWS Systems Manager Parameter Store

    Why it's wrong here

    AWS Systems Manager Parameter Store is designed for storing configuration data and some sensitive information using SecureString parameters, which are encrypted with AWS KMS. However, it lacks native, built-in support for automatic rotation of secrets, especially for database credentials. While it can store secrets, managing their lifecycle, including regular rotation, would require significant custom automation and external scheduling, making it less suitable than a dedicated secrets management service for this requirement.

  • Amazon DynamoDB

    Why it's wrong here

    Amazon DynamoDB is a fully managed, high-performance NoSQL database service designed for storing and retrieving structured and semi-structured data at scale. It is fundamentally a data storage solution, not a service for managing the lifecycle of application credentials or secrets. Using DynamoDB to store database credentials would require extensive custom development for encryption, access control, and, critically, the implementation of a robust rotation mechanism, which are all features natively provided by a secrets management service.

  • AWS KMS

    Why it's wrong here

    AWS Key Management Service (KMS) is a service that enables you to create and manage cryptographic keys and control their use across a wide range of AWS services and in your applications. While KMS is essential for encrypting the secrets stored in services like Secrets Manager or Parameter Store, it does not store the secrets themselves. Its primary function is to provide the cryptographic keys for encryption and decryption, not to manage the secret values or their rotation lifecycle.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

6 more ways this is tested on DVA-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A developer needs to securely store database credentials for a Lambda function. Which AWS service should be used?

easy
  • A.AWS Secrets Manager
  • B.AWS CloudHSM
  • C.AWS KMS
  • D.Amazon DynamoDB

Why A: AWS Secrets Manager is the correct service because it is purpose-built for securely storing, rotating, and managing database credentials and other secrets throughout their lifecycle. It integrates natively with Lambda via the AWS Secrets Manager API, allowing the function to retrieve credentials at runtime without hardcoding them, and supports automatic rotation using built-in or custom Lambda rotation functions. This makes it the ideal choice for securely handling database credentials in a serverless application.

Variation 2. A developer needs to securely store database credentials for a Lambda function. The credentials should be automatically rotated every 30 days. Which AWS service should the developer use?

easy
  • A.AWS Key Management Service (KMS) to encrypt the credentials.
  • B.Store the credentials in an IAM role's trust policy.
  • C.AWS Secrets Manager.
  • D.AWS Systems Manager Parameter Store with a SecureString parameter.

Why C: AWS Secrets Manager is the correct choice because it is specifically designed to securely store, manage, and automatically rotate database credentials and other secrets. It supports native rotation of credentials for Amazon RDS, Redshift, and DocumentDB with built-in Lambda rotation functions, and can be configured to rotate on a schedule (e.g., every 30 days) without custom code. The service also integrates directly with Lambda via the AWS SDK to retrieve secrets at runtime, ensuring credentials are never hardcoded.

Variation 3. A developer wants to securely store database credentials for a Lambda function. Which AWS service should be used?

easy
  • A.AWS Secrets Manager
  • B.AWS Systems Manager Parameter Store
  • C.Amazon S3 with server-side encryption
  • D.Amazon DynamoDB

Why A: AWS Secrets Manager is specifically designed for secure storage and automatic rotation of database credentials. Option B (Systems Manager Parameter Store) can store secrets but lacks native automatic rotation capabilities, making it less suitable for this use case. Option C (S3 with server-side encryption) is not a dedicated secrets store and would require additional access control management. Option D (DynamoDB) is a NoSQL database, not a secret management service, and would require custom encryption and rotation logic.

Variation 4. A developer wants to securely store database credentials used by a Lambda function. The credentials should be automatically rotated every 90 days. Which service should be used?

easy
  • A.AWS Secrets Manager
  • B.AWS Key Management Service (KMS)
  • C.AWS Identity and Access Management (IAM)
  • D.AWS Systems Manager Parameter Store

Why A: AWS Secrets Manager is the correct choice because it is purpose-built for securely storing, retrieving, and automatically rotating database credentials and other secrets. It supports native rotation with built-in integration for Amazon RDS (MySQL, PostgreSQL, Oracle, SQL Server, MariaDB) and Amazon DocumentDB, allowing you to configure automatic rotation every 90 days without custom code. The service encrypts secrets at rest using AWS KMS and enforces fine-grained access control via IAM policies.

Variation 5. A developer needs to securely store database credentials and retrieve them programmatically from a Lambda function. Which AWS services can be used for this purpose? (Choose TWO.)

easy
  • A.AWS Systems Manager Parameter Store (SecureString)
  • B.AWS Secrets Manager
  • C.AWS CloudFormation
  • D.AWS Identity and Access Management (IAM)
  • E.Amazon S3

Why A: Options A and B are correct. AWS Systems Manager Parameter Store (SecureString) and AWS Secrets Manager are both designed to securely store database credentials and other secrets, and allow programmatic retrieval from Lambda functions. AWS CloudFormation (option C) is for infrastructure as code, not for storing secrets. AWS IAM (option D) is for managing permissions, not for storing secrets. Amazon S3 (option E) is for object storage and is not a secure secrets management service.

Variation 6. A developer needs to encrypt secrets such as database passwords used by an application running on EC2. Which AWS service should be used to securely store and rotate these secrets?

medium
  • A.AWS CloudHSM
  • B.AWS Secrets Manager
  • C.AWS KMS
  • D.AWS Systems Manager Parameter Store

Why B: AWS Secrets Manager is the correct choice because it is specifically designed to securely store, manage, and automatically rotate secrets such as database passwords, API keys, and other credentials. It integrates natively with AWS services like RDS, Redshift, and DocumentDB to enable automatic rotation of secrets without custom code, and it enforces encryption at rest using AWS KMS. This makes it the ideal service for the use case described, where secrets must be both stored securely and rotated automatically.

Last reviewed: Jun 24, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.