Courseiva

DOP-C02 Configuration Management and IaC Practice Question

Which TWO approaches can be used to manage configuration files (e.g., application.properties) across multiple AWS accounts and regions using AWS Systems Manager? (Select TWO.)

⚠ Common exam trap

It's easy for candidates to confuse AWS Secrets Manager with Parameter Store for configuration management, or assume Run Command is suitable for configuration deployment, when in fact AppConfig and Parameter Store are the correct Systems Manager services for managing and deploying configuration files across multiple accounts and regions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use AWS AppConfig to create, manage, and deploy application configurations across accounts and regions.

AWS AppConfig is a feature of AWS Systems Manager that allows you to create, manage, and deploy application configurations across accounts and regions. It supports staged rollouts, validation, and monitoring, making it suitable for managing configuration files like application.properties in multi-account, multi-region environments.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use AWS AppConfig to create, manage, and deploy application configurations across accounts and regions.

    Why this is correct

    AWS AppConfig is the correct choice because it is purpose-built for managing application configuration independently of code deployments. It supports creating and maintaining configurations in a central store, validating them with format or semantic checks, and rolling them out gradually across accounts and regions using deployment strategies. Unlike the other options, AppConfig also provides built-in monitoring, automatic rollback, and the ability to retrieve configuration at runtime, making it an enterprise-grade configuration management service.

  • ✗

    Use AWS OpsWorks for Chef Automate to store configuration data in Chef data bags.

    Why it's wrong here

    AWS OpsWorks for Chef Automate is not a suitable approach for this use case because it is primarily a configuration management service for operating servers, not a centralized store for application configuration data across accounts. Chef data bags are node-specific data structures tied to Chef infrastructure and require a Chef server to manage, which adds operational overhead and does not provide the cross-account, application-facing configuration retrieval and validation features needed here.

  • ✗

    Store configuration files in AWS Secrets Manager and retrieve them using the Secrets Manager API.

    Why it's wrong here

    AWS Secrets Manager is designed to protect and rotate secrets such as database credentials and API keys, not to store general configuration files or application parameters. While it can technically store binary or text values, its API is optimized for infrequent retrieval of highly sensitive data, and it lacks configuration-specific features like schema validation, staged rollouts, and deployment strategies. Additionally, frequent reads would incur unnecessary cost and latency compared to appropriate configuration stores.

  • ✓

    Store configuration parameters in AWS Systems Manager Parameter Store and reference them from applications using the AWS SDK.

    Why this is correct

    AWS Systems Manager Parameter Store is also correct because it offers a scalable, hierarchical key-value store for configuration data and can be accessed from applications using the AWS SDK. Parameter Store supports both standard and advanced parameters, allows tagging and IAM access control, and can be made accessible across accounts through resource-based policies or IAM roles. It integrates with AWS Lambda, ECS, EC2, and other services, making it a natural fit for storing non-secret configuration parameters that applications can query on demand.

  • ✗

    Use AWS Systems Manager Run Command to push configuration files to EC2 instances on demand.

    Why it's wrong here

    AWS Systems Manager Run Command is a wrong approach because it is an operational tool for executing commands and scripts on managed instances, not a service for storing or managing configuration files. While you could use Run Command to copy files to EC2 instances, it does not provide a central configuration repository, validation, versioning, or rollout controls, and it would not support cross-account configuration management or runtime retrieval by applications. It solves a different problem—remote command execution—rather than configuration storage and distribution.

About these practice questions

Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.