Courseiva
SDLC Automation →mediumMultiple Choice

DOP-C02 SDLC Automation Practice Question

A company uses AWS CloudFormation to manage infrastructure as code. They have a stack that creates an Amazon RDS database instance. The database password is stored as a parameter in AWS Systems Manager Parameter Store. The CloudFormation template references the parameter using the 'resolve:ssm' dynamic reference. Recently, a security audit found that the password was exposed in plaintext in the CloudFormation stack outputs. The team wants to prevent sensitive information from being displayed in stack outputs or logs. Which approach should be taken?

⚠ Common exam trap

DOP-C02 often tests the misconception that NoEcho protects a value everywhere in the template — candidates must remember NoEcho only masks parameters during stack operations and does nothing for Outputs, which are always plaintext.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Remove the output from the CloudFormation stack

The exposure occurred because the sensitive value was placed in the CloudFormation stack Outputs section, which is always visible in plaintext via the console, CLI (describe-stacks), and API regardless of NoEcho or KMS. The only reliable fix is to remove the sensitive value from Outputs entirely and instead surface it through a secure channel such as Secrets Manager, SSM Parameter Store (SecureString), or a custom resource. NoEcho only masks parameter values in the console/API during stack operations — it does not protect Outputs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Set the 'NoEcho' property to 'true' for the parameter in the template

    Why it's wrong here

    Setting the 'NoEcho' property to 'true' on a CloudFormation template parameter masks the value as asterisks when the parameter is entered through the console, API, or CLI. However, NoEcho only obscures the parameter input; it does not prevent the resolved value from a dynamic reference like 'resolve:ssm' from being evaluated and displayed in the stack outputs. When an output references the parameter, CloudFormation will resolve the actual secret value and expose it to anyone with permission to call DescribeStacks or view outputs in the console.

  • ✗

    Store the password in AWS Secrets Manager and reference it in the template

    Why it's wrong here

    Storing the password in AWS Secrets Manager and using a dynamic reference such as '{{resolve:secretsmanager:secret-id:SecretString:password}}' in the template is a recommended practice for secure secret management, but it does not protect the value in outputs. If that dynamic reference is used in an output value, CloudFormation resolves it to the actual plaintext password during stack creation/update, and that plaintext is then visible in the stack's output data. The template references the secret, but the output still exposes the final resolved string, so the sensitive value remains accessible.

  • ✓

    Remove the output from the CloudFormation stack

    Why this is correct

    Removing the output from the CloudFormation stack is the only direct way to prevent the password from being exposed in the stack's output section. Outputs are stored in plaintext by CloudFormation and are retrievable via the console, APIs such as DescribeStacks, and any logging that captures API responses. By eliminating the output, you ensure that the password does not appear in that specific exposure path; additional best practices like using Secrets Manager for retrieval by applications should still be implemented to protect the secret throughout its lifecycle.

  • ✗

    Encrypt the output value using AWS KMS

    Why it's wrong here

    CloudFormation does not support encrypting individual output values with AWS KMS. Stack outputs are plaintext key-value pairs stored as part of the stack metadata, intended for informational or cross-stack purposes, and they are returned by actions like DescribeStacks without any server-side encryption specific to each output. While KMS can encrypt other CloudFormation-related artifacts (like template bodies or S3 artifacts via encryption settings), there is no mechanism to encrypt output fields themselves, so this approach cannot prevent the password from being displayed.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.