Courseiva
Security and Compliance →mediumMultiple Choice

DOP-C02 Security and Compliance Practice Question

A DevOps engineer needs to securely store and automatically rotate database credentials for a web application running on Amazon ECS. Which solution should be used?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Store the credentials in AWS Secrets Manager and configure rotation. Grant the ECS task IAM role permission to retrieve the secret.

AWS Secrets Manager can store database credentials and automatically rotate them on a schedule. The ECS task can retrieve the credentials using the Secrets Manager secret. Option C is correct. Option A (AWS KMS) is for encryption keys, not credential rotation. Option B (SSM Parameter Store) can store secrets but does not support automatic rotation. Option D (AWS Certificate Manager) is for SSL/TLS certificates.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use AWS KMS to generate and rotate a data key for encrypting the credentials in a file on ECS.

    Why it's wrong here

    AWS KMS is a key management service that creates and controls encryption keys, not rotating the underlying secret value. Using GenerateDataKey to encrypt a credential file on ECS protects the file at rest, but the database password itself remains unchanged and must be rotated manually or through a separate process. Envelope encryption with a KMS data key does not address the requirement for automatic credential rotation; it only addresses encryption of stored data.

  • ✗

    Store the credentials in AWS Systems Manager Parameter Store as a SecureString. Use a Lambda function to rotate them.

    Why it's wrong here

    SSM Parameter Store can store credentials as a SecureString using KMS encryption, but it has no native rotation capability. You could create a custom Lambda function to generate a new password and update both the parameter and the database, but that requires you to build and operate the entire rotation workflow, including scheduling and error handling. AWS Secrets Manager is the managed service designed for this exact use case, so this option puts unnecessary operational burden on the engineer and does not provide built-in automatic rotation.

  • ✓

    Store the credentials in AWS Secrets Manager and configure rotation. Grant the ECS task IAM role permission to retrieve the secret.

    Why this is correct

    AWS Secrets Manager natively supports automatic rotation of secrets with a configurable rotation schedule, using a Lambda function that updates the secret in both Secrets Manager and the target database. The ECS task assumes an IAM role whose permissions include secretsmanager:GetSecretValue, allowing the container to fetch the current password at runtime without embedding it in the task definition. This approach centralizes secret storage, enables rotation without redeploying the ECS service, and follows AWS best practices for managing database credentials.

  • ✗

    Use AWS Certificate Manager to store the credentials as a certificate.

    Why it's wrong here

    AWS Certificate Manager is specifically designed to provision, manage, and deploy public and private X.509 TLS certificates used to encrypt network traffic. It cannot store arbitrary database credentials or any other key-value secrets, nor does it have a mechanism to rotate database passwords. Using ACM for this purpose is a fundamental misuse of the service, as it provides no API to retrieve a secret value for an application to use as a database password.

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on DOP-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which TWO AWS services can be used to manage and rotate database credentials automatically? (Select TWO.)

easy
  • ✓ A.AWS Systems Manager Parameter Store
  • ✓ B.AWS Secrets Manager
  • C.AWS CloudFormation
  • D.AWS KMS
  • E.AWS IAM

Why A: AWS Secrets Manager (B) is correct because it is purpose-built to store, manage, and automatically rotate database credentials using built-in Lambda rotation functions for supported engines like Amazon RDS, Aurora, Redshift, and DocumentDB. AWS Systems Manager Parameter Store (A) is also correct because it can store database credentials as SecureString parameters and, when integrated with Secrets Manager rotation or custom Lambda rotation logic, supports managing and rotating those credentials automatically. AWS CloudFormation (C) is incorrect because it is an infrastructure-as-code provisioning service, not a credential rotation mechanism. AWS KMS (D) is incorrect because it provides encryption key management and cryptographic operations, not credential lifecycle or rotation. AWS IAM (E) is incorrect because it manages identities, permissions, and roles, not database credential storage or automatic rotation.

Variation 2. A DevOps engineer needs to securely store and automatically rotate database credentials for a MySQL RDS instance. The credentials should be accessible to a Lambda function without hardcoding them. Which AWS service should be used?

easy
  • A.AWS Systems Manager Parameter Store
  • ✓ B.AWS Secrets Manager
  • C.AWS Key Management Service (KMS)
  • D.IAM roles for EC2

Why B: AWS Secrets Manager is the correct service because it allows you to store secrets, automatically rotate them for supported RDS databases, and retrieve them programmatically via the Lambda runtime using the Secrets Manager API. AWS Systems Manager Parameter Store can store secrets but does not natively support automatic rotation for RDS. AWS KMS is used for managing encryption keys, not storing secrets. IAM roles for EC2 provide permissions to EC2 instances but cannot store credentials.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.