Courseiva
Security →easyMultiple Choice

DVA-C02 Security Practice Question

A developer wants to securely store database credentials for a Lambda function. Which AWS service should be used?

⚠ Common exam trap

DVA-C02 often tests the distinction between Secrets Manager and Parameter Store — candidates pick Parameter Store because it can store SecureStrings, but the question's emphasis on 'database credentials' signals Secrets Manager's native rotation capability.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Secrets Manager

AWS Secrets Manager is purpose-built for storing, rotating, and retrieving sensitive credentials such as database passwords. It integrates natively with Lambda via the AWS SDK, supports automatic rotation using Lambda rotation functions, and encrypts secrets with KMS. For database credentials specifically, Secrets Manager's built-in RDS/Redshift/DocumentDB rotation templates make it the recommended service.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    AWS Secrets Manager

    Why this is correct

    AWS Secrets Manager is the optimal choice as it is purpose-built for managing, retrieving, and rotating database credentials, API keys, and other secrets throughout their lifecycle. It offers native integration with services like Amazon RDS and Amazon Redshift for automatic credential rotation, enhancing security by regularly changing credentials without application downtime. Furthermore, it provides fine-grained access control through AWS IAM and comprehensive auditing via AWS CloudTrail, ensuring secure and compliant secret management.

  • ✗

    AWS Systems Manager Parameter Store

    Why it's wrong here

    AWS Systems Manager Parameter Store can securely store configuration data and generic secrets as SecureString parameters, encrypting them with KMS. However, it lacks the specialized features for managing database credentials that Secrets Manager provides, such as native automatic rotation for database credentials and direct integration with database services. While it can store secrets, implementing a robust rotation strategy for database credentials would require significant custom automation, making it less efficient and more prone to errors than Secrets Manager.

  • ✗

    Amazon S3 with server-side encryption

    Why it's wrong here

    While Amazon S3 can store data encrypted at rest using server-side encryption (SSE-S3, SSE-KMS, SSE-C), it is fundamentally an object storage service and not designed for active secret management. Storing database credentials in S3 would necessitate building a complex custom solution for access control, credential retrieval, and rotation, which is prone to security vulnerabilities and operational overhead. It lacks the API-driven secret retrieval, versioning, and lifecycle management capabilities essential for secure and scalable credential handling.

  • ✗

    Amazon DynamoDB

    Why it's wrong here

    Amazon DynamoDB is a fast, flexible NoSQL database service designed for application data storage, not for secret management. Although data can be encrypted at rest, DynamoDB lacks the specialized features required for secure credential lifecycle management, such as automatic rotation, secret versioning, and direct integration with application credential providers. Using DynamoDB for secrets would require developing and maintaining a custom secret management layer, which is inefficient, introduces unnecessary complexity, and does not leverage a purpose-built security service.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

This DVA-C02 question is part of Courseiva's 1,135-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.