DOP-C02 Configuration Management and IaC Practice Question
A DevOps team uses Ansible for configuration management of EC2 instances. They want to ensure that the Ansible control node can connect to managed nodes securely without storing SSH keys in plaintext. Which AWS service should they integrate with Ansible to securely manage SSH keys?
⚠ Common exam trap
DOP-C02 often tests the distinction between services that store secrets (Secrets Manager, Parameter Store) and services that encrypt or authorize (KMS, IAM), so candidates who pick KMS or IAM miss the requirement for dynamic secret retrieval.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Secrets Manager to store the SSH private keys and retrieve them dynamically.
AWS Secrets Manager is designed to store, rotate, and retrieve secrets such as SSH private keys programmatically, and Ansible can integrate with it via lookup plugins or dynamic inventory to fetch keys at runtime without persisting them in plaintext on the control node. This satisfies the requirement of secure, dynamic key management with rotation support.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS KMS to encrypt the SSH keys at rest.
Why it's wrong here
AWS KMS is a key management and cryptographic service that generates and protects encryption keys, not a secret store for private key material. You could use KMS to encrypt the SSH key at rest, but you would still need a separate service such as Secrets Manager or S3 to hold the encrypted blob, and then the Ansible control node must call KMS Decrypt to recover the plaintext key. KMS also does not provide secret rotation, versioning for credentials, or a retrieval API designed for Ansible to consume directly, so it is not the appropriate service for storing and dynamically retrieving SSH private keys.
- ✓
AWS Secrets Manager to store the SSH private keys and retrieve them dynamically.
Why this is correct
AWS Secrets Manager is the correct choice because it is purpose-built for storing sensitive credentials such as SSH private keys and exposing them to applications through a controlled API. Ansible can call GetSecretValue at runtime to retrieve the key, eliminating hardcoded keys in playbooks or source control, and you can enforce IAM policies to restrict which roles and users can access the secret. Secrets Manager also supports automatic secret rotation, which lets you periodically rotate SSH keys without changing Ansible configuration, and it can be integrated directly with Ansible modules or AWS CLI calls.
- ✗
AWS IAM roles to grant Ansible access to the instances.
Why it's wrong here
IAM roles grant temporary AWS API credentials to EC2 instances so that software on the instance can call AWS services, but they do not provide SSH authentication or store SSH private keys. Ansible connects to target instances over SSH using a private key, and IAM roles cannot be used as an SSH credential or injected into the SSH client as a key. Therefore, even with an instance role attached, Ansible still needs the private key material from a secret store to authenticate to the managed nodes.
- ✗
AWS Systems Manager Parameter Store to store the keys.
Why it's wrong here
AWS Systems Manager Parameter Store can store SSH private keys as SecureString parameters, but it is a general-purpose configuration and parameter store rather than a dedicated secrets management service. It lacks native automatic rotation for SSH keys and has a lower feature set around secret lifecycle management, access auditing, and cross-account sharing compared to Secrets Manager. While it can be made to work, using Parameter Store for SSH private keys is less suited because it doesn't provide the same built-in protections and automation that Secrets Manager offers, making Secrets Manager the best answer.
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.