DOP-C02 Security and Compliance Practice Question
A DevOps engineer is responsible for securing a containerized application running on Amazon ECS with the Fargate launch type. The application needs to access an Amazon RDS database and an Amazon S3 bucket. The security team requires that credentials are not hardcoded and that access is least privilege. Which two actions should the engineer take to meet these requirements? (Choose two.)
⚠ Common exam trap
The trap here is thinking that environment variables or Parameter Store plaintext are acceptable for secrets, when they lack encryption and rotation, and that an IAM user with embedded keys is safe when it is actually a major security risk.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Store the database credentials in AWS Secrets Manager and grant the ECS task role permission to retrieve them.
The secure approach is to use an IAM task role for AWS service access and AWS Secrets Manager for database credentials. The task role provides temporary credentials for S3 and Secrets Manager, while Secrets Manager securely stores and can rotate the database password. This combination avoids hardcoded credentials and supports least privilege.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Store the database credentials in AWS Secrets Manager and grant the ECS task role permission to retrieve them.
Why this is correct
Secrets Manager securely stores and rotates credentials. By granting the ECS task role permission to retrieve the secret, the application can fetch credentials at runtime without hardcoding them. This aligns with least privilege and eliminates static credentials in code or environment variables.
- ✗
Configure the ECS task definition to use environment variables for the database password.
Why it's wrong here
Environment variables in task definitions are visible in the ECS console and API, and they are not encrypted at rest by default. This exposes sensitive credentials and violates the requirement to avoid hardcoding. While convenient, it is not a secure method for storing secrets.
- ✗
Use AWS Systems Manager Parameter Store to store the database credentials as plaintext strings.
Why it's wrong here
Parameter Store can store secrets, but storing them as plaintext does not meet security best practices. Secrets Manager is preferred for database credentials because it offers automatic rotation and fine-grained access control. Plaintext storage also lacks encryption by default, increasing risk.
- ✗
Create an IAM user with programmatic access and embed the access keys in the container image.
Why it's wrong here
Embedding access keys in a container image is insecure and violates the requirement to avoid hardcoded credentials. It also grants long-term credentials that are difficult to rotate and can be exposed if the image is compromised. This approach is not least privilege and should be avoided.
- ✓
Attach an IAM role to the ECS task that grants access to the S3 bucket and Secrets Manager secret.
Why this is correct
ECS task roles provide temporary credentials to containers. By attaching a role with least-privilege permissions for S3 and Secrets Manager, the application can access both services securely without managing long-term credentials. This is the recommended way to grant AWS permissions to ECS tasks.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.