DVA-C02 Security Practice Question
A developer needs to securely store database credentials for a Lambda function. The credentials must be automatically rotated every 90 days. Which AWS service should be used?
⚠ Common exam trap
It's easy for candidates to confuse AWS Systems Manager Parameter Store (which can store secrets securely but lacks automatic rotation) with AWS Secrets Manager, leading them to choose Parameter Store when the question explicitly requires automatic rotation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Secrets Manager
AWS Secrets Manager is the correct service because it is designed specifically for securely storing, managing, and automatically rotating database credentials and other secrets. It supports built-in rotation with AWS Lambda, allowing you to set a custom rotation interval (e.g., 90 days) without custom infrastructure. Secrets Manager also integrates natively with Amazon RDS, Redshift, and DocumentDB for automatic credential rotation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS Secrets Manager
Why this is correct
AWS Secrets Manager is the correct choice because it is purpose-built for securely storing, managing, and retrieving sensitive credentials like database passwords, API keys, and other secrets. A key feature is its ability to automatically rotate secrets, including integrating with databases to generate new credentials and update the database directly. This automation significantly enhances security by regularly changing credentials without manual intervention, reducing the risk of compromise and ensuring compliance with security best practices.
- ✗
AWS Systems Manager Parameter Store
Why it's wrong here
AWS Systems Manager Parameter Store is designed for storing configuration data and some sensitive information using SecureString parameters, which are encrypted with AWS KMS. However, it lacks native, built-in support for automatic rotation of secrets, especially for database credentials. While it can store secrets, managing their lifecycle, including regular rotation, would require significant custom automation and external scheduling, making it less suitable than a dedicated secrets management service for this requirement.
- ✗
Amazon DynamoDB
Why it's wrong here
Amazon DynamoDB is a fully managed, high-performance NoSQL database service designed for storing and retrieving structured and semi-structured data at scale. It is fundamentally a data storage solution, not a service for managing the lifecycle of application credentials or secrets. Using DynamoDB to store database credentials would require extensive custom development for encryption, access control, and, critically, the implementation of a robust rotation mechanism, which are all features natively provided by a secrets management service.
- ✗
AWS KMS
Why it's wrong here
AWS Key Management Service (KMS) is a service that enables you to create and manage cryptographic keys and control their use across a wide range of AWS services and in your applications. While KMS is essential for encrypting the secrets stored in services like Secrets Manager or Parameter Store, it does not store the secrets themselves. Its primary function is to provide the cryptographic keys for encryption and decryption, not to manage the secret values or their rotation lifecycle.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DVA-C02 question from scratch — 1,135 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
6 more ways this is tested on DVA-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A developer needs to securely store database credentials for a Lambda function. Which AWS service should be used?
easy- ✓ A.AWS Secrets Manager
- B.AWS CloudHSM
- C.AWS KMS
- D.Amazon DynamoDB
Why A: AWS Secrets Manager is the correct service because it is purpose-built for securely storing, rotating, and managing database credentials and other secrets throughout their lifecycle. It integrates natively with Lambda via the AWS Secrets Manager API, allowing the function to retrieve credentials at runtime without hardcoding them, and supports automatic rotation using built-in or custom Lambda rotation functions. This makes it the ideal choice for securely handling database credentials in a serverless application.
Variation 2. A developer needs to securely store database credentials for a Lambda function. The credentials should be automatically rotated every 30 days. Which AWS service should the developer use?
easy- A.AWS Key Management Service (KMS) to encrypt the credentials.
- B.Store the credentials in an IAM role's trust policy.
- ✓ C.AWS Secrets Manager.
- D.AWS Systems Manager Parameter Store with a SecureString parameter.
Why C: AWS Secrets Manager is the correct choice because it is specifically designed to securely store, manage, and automatically rotate database credentials and other secrets. It supports native rotation of credentials for Amazon RDS, Redshift, and DocumentDB with built-in Lambda rotation functions, and can be configured to rotate on a schedule (e.g., every 30 days) without custom code. The service also integrates directly with Lambda via the AWS SDK to retrieve secrets at runtime, ensuring credentials are never hardcoded.
Variation 3. A developer wants to securely store database credentials for a Lambda function. Which AWS service should be used?
easy- ✓ A.AWS Secrets Manager
- B.AWS Systems Manager Parameter Store
- C.Amazon S3 with server-side encryption
- D.Amazon DynamoDB
Why A: AWS Secrets Manager is purpose-built for storing, rotating, and retrieving sensitive credentials such as database passwords. It integrates natively with Lambda via the AWS SDK, supports automatic rotation using Lambda rotation functions, and encrypts secrets with KMS. For database credentials specifically, Secrets Manager's built-in RDS/Redshift/DocumentDB rotation templates make it the recommended service.
Variation 4. A developer wants to securely store database credentials used by a Lambda function. The credentials should be automatically rotated every 90 days. Which service should be used?
easy- ✓ A.AWS Secrets Manager
- B.AWS Key Management Service (KMS)
- C.AWS Identity and Access Management (IAM)
- D.AWS Systems Manager Parameter Store
Why A: AWS Secrets Manager is the correct choice because it is purpose-built for securely storing, retrieving, and automatically rotating database credentials and other secrets. It supports native rotation with built-in integration for Amazon RDS (MySQL, PostgreSQL, Oracle, SQL Server, MariaDB) and Amazon DocumentDB, allowing you to configure automatic rotation every 90 days without custom code. The service encrypts secrets at rest using AWS KMS and enforces fine-grained access control via IAM policies.
Variation 5. A developer needs to securely store database credentials and retrieve them programmatically from a Lambda function. Which AWS services can be used for this purpose? (Choose TWO.)
easy- ✓ A.AWS Systems Manager Parameter Store (SecureString)
- ✓ B.AWS Secrets Manager
- C.AWS CloudFormation
- D.AWS Identity and Access Management (IAM)
- E.Amazon S3
Why A: AWS Systems Manager Parameter Store (SecureString) [CORRECT] is right because it stores sensitive values like database credentials as encrypted parameters using KMS, and a Lambda function can retrieve them programmatically via the GetParameter API with the WithDecryption flag set to true. AWS Secrets Manager [CORRECT] is also right because it is purpose-built for storing and rotating secrets such as database credentials, and Lambda can retrieve them programmatically using the GetSecretValue API. AWS CloudFormation does not belong because it is an infrastructure-as-code service for provisioning resources, not a secrets store for runtime retrieval. AWS Identity and Access Management (IAM) does not belong because it manages permissions and identities, not the storage of credential values themselves. Amazon S3 does not belong because it is object storage and, while it can hold files, it is not designed as a secure credential store with native secret-retrieval APIs for this use case.
Variation 6. A developer needs to encrypt secrets such as database passwords used by an application running on EC2. Which AWS service should be used to securely store and rotate these secrets?
medium- A.AWS CloudHSM
- ✓ B.AWS Secrets Manager
- C.AWS KMS
- D.AWS Systems Manager Parameter Store
Why B: AWS Secrets Manager is the correct choice because it is specifically designed to securely store, manage, and automatically rotate secrets such as database passwords, API keys, and other credentials. It integrates natively with AWS services like RDS, Redshift, and DocumentDB to enable automatic rotation of secrets without custom code, and it enforces encryption at rest using AWS KMS. This makes it the ideal service for the use case described, where secrets must be both stored securely and rotated automatically.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.