Courseiva

DOP-C02 Configuration Management and IaC Practice Question

A DevOps team uses AWS CodeCommit and AWS CodePipeline for CI/CD. They need to ensure that sensitive configuration parameters such as database passwords are not stored in plaintext in the source code repository. Which solution meets these requirements with minimal operational overhead?

⚠ Common exam trap

Candidates often think storing an encrypted blob in the repository (Option B) is acceptable because it is 'encrypted,' but the exam tests the principle that secrets should never be stored in the source code repository at all, even in encrypted form, due to key management and exposure risks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use AWS Systems Manager Parameter Store with secure strings, and reference them in the pipeline using parameter-store action.

AWS Systems Manager Parameter Store with secure strings provides a native, fully managed service for storing sensitive configuration data like database passwords. By using the parameter-store action in CodePipeline, the pipeline can retrieve the secure parameter at runtime without exposing it in the source code or requiring manual encryption/decryption logic, minimizing operational overhead.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Store the parameters in a separate encrypted Git repository and use Git submodules.

    Why it's wrong here

    Encrypting a separate Git repository does not keep secrets out of your pipeline: at build time the submodule must be decrypted, and the plaintext secret is then present in the CodeBuild workspace where any logging or artifact packaging can expose it. Git also retains every historical copy of the secret, and managing submodule SSH/HTTPS credentials adds yet another secret to rotate.

  • ✗

    Use AWS KMS to encrypt the parameters and include the encrypted blob in the source code.

    Why it's wrong here

    Wrapping a secret with KMS before committing it to source merely substitutes a ciphertext blob for plaintext; the blob still lives in the repo and any principal with access to the KMS key can decrypt it at runtime. Because the decryption logic and the encrypted secret are both in code, a leak of the repository—or a malicious log line that prints the variable—directly defeats the encryption, and you now have to manage KMS key permissions for every build environment.

  • ✗

    Store the parameters in an S3 bucket with server-side encryption, and have the pipeline download them.

    Why it's wrong here

    Server-side encryption in S3 protects the object at rest, but the pipeline action that downloads the object must decrypt it into the build workspace, leaving a plaintext file that can be accidentally included in build output, copied into artifacts, or echoed into logs. You also introduce an extra dependency: the bucket, the object versioning, and the IAM role to access it all become operational overhead that Parameter Store avoids.

  • ✓

    Use AWS Systems Manager Parameter Store with secure strings, and reference them in the pipeline using parameter-store action.

    Why this is correct

    AWS Systems Manager Parameter Store with a SecureString parameter encrypts the secret under a KMS customer managed key and lets CodePipeline or CodeBuild retrieve it directly as an environment variable at build time, without the secret ever appearing in the source repository or build artifact. Because access is controlled via IAM, you can scope which pipelines see which secrets, and you can rely on Parameter Store’s native versioning to rotate values without triggering a pipeline rebuild.

About these practice questions

Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.