Three Methods to Securely Pass Credentials to ECS Fargate Tasks
A developer is deploying a containerized application on Amazon ECS with Fargate. The application requires access to an Amazon RDS database. The developer needs to securely pass database credentials to the container. Which THREE methods can the developer use?
Quick Answer
The answer is to use IAM roles for tasks and retrieve credentials from AWS Secrets Manager at runtime, along with storing credentials in AWS Systems Manager Parameter Store or using IAM database authentication for RDS. These three methods are correct because they eliminate hardcoded secrets and leverage AWS’s native security services to grant temporary, scoped access—IAM roles for tasks provide an identity to the container, while Secrets Manager and Parameter Store encrypt credentials at rest and in transit, allowing the application to fetch them securely at startup. On the AWS Certified Developer Associate DVA-C02 exam, this question tests your understanding of the shared responsibility model and the principle of least privilege; a common trap is assuming environment variables in the task definition are safe, but they are stored in plain text and visible in the AWS console. Remember the mnemonic “I SPY” for IAM roles, Secrets Manager, Parameter Store, and IAM database auth—four secure paths, but only three fit this scenario.
⚠ Common exam trap
Many exam-takers confuse 'referencing a secret in the task definition' (which is secure and done at launch time) with 'defining environment variables directly in the task definition' (which is insecure), and they may also overlook that IAM roles for tasks can be used to retrieve secrets at runtime, not just at launch.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Store the credentials in AWS Systems Manager Parameter Store and reference the parameter in the task definition.
Options A, B, and C are correct because they all provide secure, native mechanisms for delivering RDS credentials to an ECS Fargate task. Option A is right because ECS task definitions support the secrets parameter with valueFrom pointing to a Systems Manager Parameter Store parameter (for example, arn:aws:ssm:region:account:parameter/name), and the value is injected at container start without being baked into the image. Option B is right because ECS also supports referencing AWS Secrets Manager secrets in the task definition's secrets block, allowing the credential to be fetched and injected securely at runtime. Option C is right because an IAM task role can grant the container permission to call secretsmanager:GetSecretValue (or ssm:GetParameter) at runtime, letting the application retrieve credentials dynamically without embedding them. Option D is wrong because hardcoding credentials in the container image exposes them to anyone who can pull or inspect the image and violates credential-rotation best practices. Option E is wrong because defining credentials as plaintext environment variables in the task definition stores them in the task definition itself, making them visible to anyone with ECS read access and not securely encrypted or rotated.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Store the credentials in AWS Systems Manager Parameter Store and reference the parameter in the task definition.
Why this is correct
Storing credentials as a SecureString parameter in Systems Manager Parameter Store and referencing it via the task definition's secrets block injects the value at container start, satisfying the requirement to pass database credentials securely without hardcoding them in the image or environment variables.
- ✓
Store the credentials in AWS Secrets Manager and reference the secret in the task definition.
Why this is correct
Secrets Manager injects credentials as environment variables or a mounted file at container start, satisfying the requirement to pass database credentials securely without hardcoding them. The task definition's secrets block references the secret ARN, so Fargate retrieves values via the execution role, keeping them out of the image and source control.
- ✓
Use IAM roles for tasks and retrieve credentials from AWS Secrets Manager at runtime.
Why this is correct
IAM roles for tasks supply temporary AWS credentials to the container, letting the application call Secrets Manager's GetSecretValue API at runtime without embedding static credentials. This satisfies the requirement to pass database credentials securely, since secrets are fetched on demand and never stored in the task definition or image.
- ✗
Hardcode the credentials in the container image.
Why it's wrong here
Hardcoding credentials in the image embeds them in every layer and registry copy, exposing them to anyone who can pull the image and preventing rotation without a rebuild. It is tempting because it requires no runtime configuration, and would only be acceptable for throwaway local test images with no real secrets.
- ✗
Define environment variables in the task definition with the credentials.
Why it's wrong here
Plain environment variables in the task definition are visible in the console, API responses and container inspection, so credentials are not securely passed. It is tempting because environment variables are the simplest way to inject configuration, and would suit non-sensitive values such as region or log level.
Go deeper
Related to this question
About these practice questions
One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on DVA-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A developer is deploying a containerized application on Amazon ECS with Fargate. The application needs to read configuration data from AWS Systems Manager Parameter Store. The developer wants to ensure that the ECS task definition can access the parameter without hardcoding the value. What should the developer do?
hard- A.Store the configuration in Amazon ECR as a label and reference it in the task definition.
- B.Use the 'configs' section in the task definition to load from Parameter Store.
- C.Add a 'parameters' section in the task definition to load from Parameter Store.
- ✓ D.Use the 'secrets' field in the task definition to reference the parameter ARN.
Why D: The 'secrets' field in an ECS task definition allows you to reference AWS Systems Manager Parameter Store (or AWS Secrets Manager) parameters by their ARN. This enables the container to retrieve the configuration value at runtime without hardcoding it in the task definition or container image, maintaining security and flexibility.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.