DOP-C02 Security and Compliance Practice Question
A company wants to securely store database credentials used by an application running on Amazon EC2. The credentials should be automatically rotated every 90 days. Which AWS service should be used?
⚠ Common exam trap
The trap is confusing Parameter Store with Secrets Manager; candidates may think Parameter Store can rotate secrets automatically, but it does not—rotation is a key differentiator of Secrets Manager.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Secrets Manager
AWS Secrets Manager is designed to securely store and manage secrets such as database credentials, and it provides built-in automatic rotation every 90 days (or custom intervals) using Lambda functions. It integrates natively with Amazon RDS, Redshift, and DocumentDB for rotation. IAM and KMS do not store secrets, and Parameter Store does not offer automatic rotation natively.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS IAM
Why it's wrong here
AWS IAM is a service for authentication and authorization, controlling which principals can perform actions on AWS resources via policies and roles. While IAM can define permissions to access secrets stored elsewhere, it does not itself store secret values or manage their lifecycle. It has no API to retrieve a database password and no mechanism for rotating credentials, so it cannot fulfill the requirement to securely store and rotate database credentials.
- ✗
AWS KMS
Why it's wrong here
AWS KMS provides cryptographic key management, creating and controlling customer master keys (KMS keys) used for encryption, decryption, and envelope encryption. It stores encryption keys and protects data at rest, but it is not a secret repository—you cannot store a plaintext database password directly inside KMS, only ciphertext that must live in another storage service. KMS also has no built-in automatic rotation of the secret value itself; rotating a KMS key would not rotate the database password it only protects.
- ✗
AWS Systems Manager Parameter Store
Why it's wrong here
AWS Systems Manager Parameter Store can store database credentials as SecureString parameters, encrypting them with AWS KMS, and integrates well with EC2 and SSM. However, it does not provide built-in automatic rotation of secret values; rotating credentials requires you to build a custom solution using Systems Manager Automation, Lambda, or third-party tooling. For a company that specifically needs managed automatic rotation of database credentials, Parameter Store lacks the native lifecycle feature that makes Secrets Manager the recommended choice.
- ✓
AWS Secrets Manager
Why this is correct
AWS Secrets Manager is purpose-built for storing secrets like database credentials and natively supports automatic rotation through an integrated Lambda rotation function. It manages secret versions with AWSCURRENT and AWSPREVIOUS labels, allowing applications to reliably fetch rotated credentials without downtime. It also provides fine-grained access via IAM and resource policies, making it the correct service when the requirement is both secure storage and automatic rotation of database credentials.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.