Courseiva
Security and Compliance →easyMultiple Choice

DOP-C02 Security and Compliance Practice Question

A DevOps engineer is designing an AWS Lambda function that needs to read secrets from AWS Secrets Manager. What is the most secure way to provide the Lambda function access to the secret?

⚠ Common exam trap

DOP-C02 often tests the misconception that encrypting a secret and storing it in an environment variable is secure, when the correct pattern is runtime retrieval via an IAM execution role scoped to the specific secret.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Assign an IAM execution role to the Lambda function with a policy that allows secretsmanager:GetSecretValue on the specific secret.

The most secure approach is to give the Lambda function an IAM execution role whose policy grants secretsmanager:GetSecretValue scoped to the specific secret's ARN. Lambda assumes this role at runtime, so no credentials are stored in code or configuration, and the secret value is retrieved dynamically, allowing rotation without redeployment. This follows least privilege and avoids hardcoding secrets.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Assign an IAM execution role to the Lambda function with a policy that allows secretsmanager:GetSecretValue on the specific secret.

    Why this is correct

    Attaching an IAM execution role with a least-privilege policy that allows secretsmanager:GetSecretValue on the specific secret ARN is the recommended pattern because it keeps the secret out of the function configuration and gives you native rotation, versioning, and CloudTrail audit events. If the secret is encrypted with a customer-managed KMS key, you must also grant kms:Decrypt on that key, but the default AWS-managed key used by Secrets Manager requires no additional KMS action. This lets the function call GetSecretValue at runtime and parse the returned JSON string without exposing the raw secret in environment variables or source code.

  • ✗

    Store the secret in AWS Systems Manager Parameter Store and grant the Lambda function access to the parameter.

    Why it's wrong here

    Using Systems Manager Parameter Store is a different service and would require separate permissions. While it can store secrets, it is not using Secrets Manager directly, and the question specifically asks for access to Secrets Manager.

  • ✗

    Encrypt the secret using AWS KMS and pass the encrypted value as an environment variable.

    Why it's wrong here

    Encrypting the secret with KMS and placing the ciphertext in an environment variable still stores the secret material in the Lambda function's configuration, so anyone with lambda:GetFunctionConfiguration can retrieve the ciphertext and, if they also have kms:Decrypt, recover the plaintext. You must embed decryption logic in the Lambda code and manage KMS key permissions, while you lose Secrets Manager's rotation, versioning, and CloudTrail audit benefits. This pattern also creates a key-management burden and a risk of plaintext being written to logs during decryption.

  • ✗

    Store the secret in an environment variable in the Lambda function.

    Why it's wrong here

    Storing a secret as a plaintext environment variable makes it immediately visible in the Lambda console to any user with read permission on the function, and it travels through infrastructure-as-code templates, CI/CD pipelines, and metadata APIs. Even though Lambda encrypts environment variables at rest with KMS, the plaintext value is exposed to any code or process with lambda:GetFunctionConfiguration, and there is no rotation, versioning, or per-secret audit capability. This violates the security principle of not embedding secrets in function configuration.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.