Courseiva

DOP-C02 Configuration Management and IaC Practice Question

A DevOps engineer needs to manage configuration files for multiple applications across several EC2 instances. The configuration values are sensitive (e.g., database passwords) and must be encrypted at rest and in transit. Which AWS service should be used to store and retrieve these configuration values?

⚠ Common exam trap

DOP-C02 often tests the distinction between a configuration store (Parameter Store) and a general-purpose data store (S3, DynamoDB), so candidates pick S3 SSE or DynamoDB encryption thinking 'encrypted at rest' is the only requirement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Systems Manager Parameter Store (SecureString)

AWS Systems Manager Parameter Store with the SecureString parameter type uses AWS KMS to encrypt values at rest and enforces TLS for values in transit, making it purpose-built for storing sensitive configuration such as database passwords. It integrates natively with EC2 instance profiles and IAM, so applications can retrieve secrets without embedding credentials in code or AMIs. This is the canonical DOP-C02 answer for encrypted configuration management.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    AWS Systems Manager Parameter Store (SecureString)

    Why this is correct

    The AWS Systems Manager Parameter Store is purpose-built for configuration management, providing a secure, hierarchical namespace for keys and values. A SecureString parameter uses AWS KMS encryption at rest and in transit, and integrates natively with EC2 via the SSM agent or SDK without exposing plaintext. It supports versioning, tagging, and IAM policies for fine-grained access, making it the right choice for dynamic runtime retrieval.

  • ✗

    AWS CloudFormation template parameters

    Why it's wrong here

    AWS CloudFormation template parameters are only substitution variables evaluated at stack creation or update time. They cannot be queried or retrieved at runtime by EC2 instances after the stack is deployed, and they lack encryption, versioning, or hierarchical organization. Using them for ongoing configuration would require redeploying or updating the stack, which is heavyweight and unsuitable for dynamic values.

  • ✗

    Amazon DynamoDB with encryption

    Why it's wrong here

    Amazon DynamoDB with encryption is a fully managed NoSQL database, not a configuration store. While you can persist configuration items, it requires designing a table schema, building retrieval logic, and managing read/write capacity, and it does not offer a built-in parameter hierarchy or secret encryption like SecureString. Retrieval from EC2 also means using the DynamoDB API directly, which introduces unnecessary complexity and latency compared to a dedicated configuration service.

  • ✗

    Amazon S3 with server-side encryption

    Why it's wrong here

    Amazon S3 with server-side encryption stores objects in a flat bucket namespace, not as hierarchical parameters, making it awkward for fine-grained configuration keys. It lacks native versioning-by-parameter, Parameter Store API semantics, and IAM integration for per-parameter access. Fetching configuration from S3 requires an EC2 instance to call S3 APIs with bucket policies, adding operational overhead without any Systems Manager integration.

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.