DOP-C02 Security and Compliance Practice Question
A DevOps engineer manages a CI/CD pipeline that builds and deploys a containerized application to an Amazon ECS cluster. The pipeline runs on an EC2 instance and needs to retrieve a secret from AWS Secrets Manager to pass to the ECS task definition. The secret must not be stored on the instance or in the pipeline's code. The engineer wants to grant the pipeline the least privilege necessary to retrieve only that specific secret. Which approach should be taken?
⚠ Common exam trap
The trap here is assuming that storing secrets in user data or environment variables is acceptable for production pipelines, when it exposes credentials to anyone with instance access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an IAM role for the EC2 instance with a policy that allows secretsmanager:GetSecretValue on the specific secret's ARN, and attach it to the instance profile.
The requirement is to retrieve a secret from AWS Secrets Manager without storing it on the instance or in code, and with least privilege. Attaching an IAM role to the EC2 instance with a policy scoped to the specific secret's ARN provides temporary credentials and restricts access. This is the most secure and operationally sound solution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Store the secret in an environment variable in the EC2 instance's user data and reference it in the pipeline.
Why it's wrong here
User data is stored in the instance metadata and is retrievable by any process on the instance. It is not encrypted at rest and can be exposed through logs or the EC2 console. This violates the requirement to not store the secret on the instance and does not provide least privilege access.
- ✗
Use AWS Systems Manager Parameter Store to store the secret as a SecureString parameter, and grant the instance's IAM role access to that parameter.
Why it's wrong here
While Parameter Store SecureString is secure, the scenario explicitly requires retrieving from AWS Secrets Manager. Parameter Store does not provide the same rotation and management features as Secrets Manager. This approach does not meet the requirement to use Secrets Manager.
- ✓
Create an IAM role for the EC2 instance with a policy that allows secretsmanager:GetSecretValue on the specific secret's ARN, and attach it to the instance profile.
Why this is correct
This approach uses an IAM role attached to the instance profile, providing temporary credentials to the pipeline. The policy scopes permissions to only the specific secret's ARN, adhering to least privilege. The secret is retrieved at runtime and never stored on the instance or in code.
- ✗
Create an IAM user with programmatic access and a policy that allows secretsmanager:GetSecretValue on all secrets, then store the access keys in AWS CodePipeline as a secret parameter.
Why it's wrong here
Using an IAM user with long-term credentials and broad permissions violates least privilege. Storing access keys in CodePipeline may be secure, but the policy grants access to all secrets, not just the specific one. This increases the blast radius if the keys are compromised.
Go deeper
Related to this question
About these practice questions
This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.