DOP-C02 Configuration Management and IaC Practice Question
A DevOps team uses AWS CodeCommit and AWS CodePipeline for CI/CD. They need to ensure that sensitive configuration parameters such as database passwords are not stored in plaintext in the source code repository. Which solution meets these requirements with minimal operational overhead?
⚠ Common exam trap
Candidates often think storing an encrypted blob in the repository (Option B) is acceptable because it is 'encrypted,' but the exam tests the principle that secrets should never be stored in the source code repository at all, even in encrypted form, due to key management and exposure risks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use AWS Systems Manager Parameter Store with secure strings, and reference them in the pipeline using parameter-store action.
AWS Systems Manager Parameter Store with secure strings provides a native, fully managed service for storing sensitive configuration data like database passwords. By using the parameter-store action in CodePipeline, the pipeline can retrieve the secure parameter at runtime without exposing it in the source code or requiring manual encryption/decryption logic, minimizing operational overhead.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Store the parameters in a separate encrypted Git repository and use Git submodules.
Why it's wrong here
Encrypting a separate Git repository does not keep secrets out of your pipeline: at build time the submodule must be decrypted, and the plaintext secret is then present in the CodeBuild workspace where any logging or artifact packaging can expose it. Git also retains every historical copy of the secret, and managing submodule SSH/HTTPS credentials adds yet another secret to rotate.
- ✗
Use AWS KMS to encrypt the parameters and include the encrypted blob in the source code.
Why it's wrong here
Wrapping a secret with KMS before committing it to source merely substitutes a ciphertext blob for plaintext; the blob still lives in the repo and any principal with access to the KMS key can decrypt it at runtime. Because the decryption logic and the encrypted secret are both in code, a leak of the repository—or a malicious log line that prints the variable—directly defeats the encryption, and you now have to manage KMS key permissions for every build environment.
- ✗
Store the parameters in an S3 bucket with server-side encryption, and have the pipeline download them.
Why it's wrong here
Server-side encryption in S3 protects the object at rest, but the pipeline action that downloads the object must decrypt it into the build workspace, leaving a plaintext file that can be accidentally included in build output, copied into artifacts, or echoed into logs. You also introduce an extra dependency: the bucket, the object versioning, and the IAM role to access it all become operational overhead that Parameter Store avoids.
- ✓
Use AWS Systems Manager Parameter Store with secure strings, and reference them in the pipeline using parameter-store action.
Why this is correct
AWS Systems Manager Parameter Store with a SecureString parameter encrypts the secret under a KMS customer managed key and lets CodePipeline or CodeBuild retrieve it directly as an environment variable at build time, without the secret ever appearing in the source repository or build artifact. Because access is controlled via IAM, you can scope which pipelines see which secrets, and you can rely on Parameter Store’s native versioning to rotate values without triggering a pipeline rebuild.
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.