DOP-C02 Configuration Management and IaC Practice Question
A DevOps team is designing a CI/CD pipeline for a microservices application deployed on Amazon ECS. The application uses multiple AWS services including RDS, ElastiCache, and SQS. Which TWO strategies should the team implement to ensure secure and auditable configuration management across environments?
⚠ Common exam trap
DOP-C02 often tests whether candidates confuse 'auditable' with 'manual' — the trap is selecting manual review or version-controlled config files because they sound like governance, when the exam expects automated, least-privilege, auditable AWS-native services.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use AWS Secrets Manager to store and rotate database credentials.
Option A is correct because AWS Secrets Manager is purpose-built to store sensitive values such as RDS database credentials and can automatically rotate them on a schedule using Lambda rotation functions, keeping secrets out of code and configuration files across all environments. Option B is correct because AWS Config continuously records resource configurations and evaluates them against rules, enabling enforcement of tagging and compliance standards and providing an auditable history of configuration changes across the ECS, RDS, ElastiCache, and SQS resources. Option C is not appropriate because storing credentials in a version-controlled file exposes secrets in source control history and provides no rotation or access auditing. Option D is not appropriate because manual review is error-prone, does not scale across environments, and provides no automated audit trail or enforcement. Option E is not appropriate because granting developers direct S3 access to upload configuration files bypasses least-privilege controls and lacks the auditing and secret-management capabilities required for secure configuration management.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use AWS Secrets Manager to store and rotate database credentials.
Why this is correct
AWS Secrets Manager natively rotates RDS credentials via Lambda, satisfying the rotation requirement for database secrets. Unlike Parameter Store, it provides built-in rotation and cross-account replication, keeping credentials out of code and pipeline variables while CloudTrail logs every retrieval for auditability across environments.
- ✓
Implement AWS Config rules to enforce tagging and compliance standards.
Why this is correct
AWS Config rules continuously evaluate resource configurations against tagging and compliance standards, recording changes for audit. This satisfies the auditable configuration management requirement by detecting drift across RDS, ElastiCache and SQS resources in every environment.
- ✗
Store database credentials in a version-controlled configuration file.
Why it's wrong here
Version control stores plaintext secrets readable by anyone with repository access, breaking confidentiality and rotation. It is tempting because committing configuration to Git gives the audit trail and change history the question demands, and would be correct for non-sensitive settings such as feature flags or environment names.
- ✗
Manually review configuration changes before deployment.
Why it's wrong here
Manual review is a human gate that leaves no automated, tamper-evident record and cannot scale across environments. It is tempting because a second pair of eyes genuinely catches errors, and would be correct where a change advisory board approves high-risk production releases under a formal ITIL process.
- ✗
Grant developers direct S3 access to upload configuration files.
Why it's wrong here
Direct S3 upload bypasses pipeline validation, versioning and approval, so configuration changes escape audit. It is tempting because S3 is a legitimate store for configuration artefacts, and would be correct when developers upload to a bucket governed by IAM policies, versioning and CloudTrail logging.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.