DVA-C02 Security Practice Question
A developer wants to securely store database credentials for a Lambda function. Which AWS service should be used?
⚠ Common exam trap
DVA-C02 often tests the distinction between Secrets Manager and Parameter Store — candidates pick Parameter Store because it can store SecureStrings, but the question's emphasis on 'database credentials' signals Secrets Manager's native rotation capability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Secrets Manager
AWS Secrets Manager is purpose-built for storing, rotating, and retrieving sensitive credentials such as database passwords. It integrates natively with Lambda via the AWS SDK, supports automatic rotation using Lambda rotation functions, and encrypts secrets with KMS. For database credentials specifically, Secrets Manager's built-in RDS/Redshift/DocumentDB rotation templates make it the recommended service.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS Secrets Manager
Why this is correct
AWS Secrets Manager is the optimal choice as it is purpose-built for managing, retrieving, and rotating database credentials, API keys, and other secrets throughout their lifecycle. It offers native integration with services like Amazon RDS and Amazon Redshift for automatic credential rotation, enhancing security by regularly changing credentials without application downtime. Furthermore, it provides fine-grained access control through AWS IAM and comprehensive auditing via AWS CloudTrail, ensuring secure and compliant secret management.
- ✗
AWS Systems Manager Parameter Store
Why it's wrong here
AWS Systems Manager Parameter Store can securely store configuration data and generic secrets as SecureString parameters, encrypting them with KMS. However, it lacks the specialized features for managing database credentials that Secrets Manager provides, such as native automatic rotation for database credentials and direct integration with database services. While it can store secrets, implementing a robust rotation strategy for database credentials would require significant custom automation, making it less efficient and more prone to errors than Secrets Manager.
- ✗
Amazon S3 with server-side encryption
Why it's wrong here
While Amazon S3 can store data encrypted at rest using server-side encryption (SSE-S3, SSE-KMS, SSE-C), it is fundamentally an object storage service and not designed for active secret management. Storing database credentials in S3 would necessitate building a complex custom solution for access control, credential retrieval, and rotation, which is prone to security vulnerabilities and operational overhead. It lacks the API-driven secret retrieval, versioning, and lifecycle management capabilities essential for secure and scalable credential handling.
- ✗
Amazon DynamoDB
Why it's wrong here
Amazon DynamoDB is a fast, flexible NoSQL database service designed for application data storage, not for secret management. Although data can be encrypted at rest, DynamoDB lacks the specialized features required for secure credential lifecycle management, such as automatic rotation, secret versioning, and direct integration with application credential providers. Using DynamoDB for secrets would require developing and maintaining a custom secret management layer, which is inefficient, introduces unnecessary complexity, and does not leverage a purpose-built security service.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
This DVA-C02 question is part of Courseiva's 1,135-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.