DOP-C02 SDLC Automation Practice Question
A company uses AWS CloudFormation to manage infrastructure. They want to deploy a stack that creates an Amazon RDS DB instance. The database password must be stored securely and rotated automatically. Which approach meets these requirements?
⚠ Common exam trap
It's easy for candidates to confuse AWS Systems Manager Parameter Store with AWS Secrets Manager, assuming both support automatic rotation, but only Secrets Manager provides native rotation capabilities for RDS credentials.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Store the password in AWS Secrets Manager and enable automatic rotation. Reference the secret in the template using a dynamic reference.
AWS Secrets Manager provides built-in capabilities for automatic password rotation, which is a requirement. By storing the password in Secrets Manager and referencing it in the CloudFormation template using a dynamic reference (e.g., `{{resolve:secretsmanager:secret-id:SecretString:password}}`), the password is never exposed in the template or parameter logs, and rotation can be configured without updating the stack. This approach meets both security and automation requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Hardcode the password in the CloudFormation template and use a NoEcho parameter.
Why it's wrong here
NoEcho only suppresses the value from console output and stack event logs, but a literal password hardcoded in the template remains readable through the AWS CloudFormation GetTemplate API and in the template copy stored in S3. Hardcoding also provides no versioning or rotation mechanism, so changing the credential requires a manual template update and redeploy. This is a security anti-pattern; CloudFormation templates should never contain plaintext secrets, even with NoEcho.
- ✗
Use AWS Key Management Service (KMS) to encrypt the password and pass it as a parameter.
Why it's wrong here
AWS KMS is a key management service, not a secret store; encrypting a password with KMS produces a ciphertext blob that you would have to pass as a parameter and then decrypt inside your application or resource. KMS key rotation changes only the encryption key, not the encrypted password value, so the underlying credential never rotates and there is no native schedule to replace it. Passing an encrypted parameter still exposes the ciphertext in the stack template and requires custom decryption logic, so it fails the rotation requirement.
- ✗
Store the password in AWS Systems Manager Parameter Store and reference it using a dynamic reference.
Why it's wrong here
Parameter Store dynamic references allow CloudFormation to resolve a SecureString at stack create or update time, but Parameter Store has no built-in rotation; you would have to build a custom Lambda to update the parameter on a schedule. The dynamic reference is resolved once during the operation, and CloudFormation does not maintain a live binding, so if the parameter is rotated later, running resources retain the old value until a future stack update re-reads it. Without managed automatic rotation, this option does not satisfy the stated requirement.
- ✓
Store the password in AWS Secrets Manager and enable automatic rotation. Reference the secret in the template using a dynamic reference.
Why this is correct
AWS Secrets Manager offers native automatic rotation through a configured Lambda function, allowing the password to be rotated on a schedule independent of CloudFormation. Referencing the secret with a dynamic reference such as {{resolve:secretsmanager:MySecret:SecretString:password}} retrieves the current value at deployment time without embedding plaintext or ciphertext in the template. This combines secure storage, versioning, managed rotation, and clean CloudFormation integration, which makes it the correct choice.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.