DOP-C02 Security and Compliance Practice Question
Which TWO AWS services can be used to manage secrets and database credentials securely? (Choose TWO.)
⚠ Common exam trap
Many exam-takers confuse AWS Systems Manager Parameter Store (which can store secure strings) with a full secrets management solution, but Parameter Store lacks native automatic rotation and is better suited for configuration data rather than database credentials that require scheduled rotation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Secrets Manager
AWS Secrets Manager is purpose-built for securely storing, rotating, and managing secrets such as database credentials, API keys, and other sensitive data. It provides built-in integration with Amazon RDS, Redshift, and DocumentDB to automatically rotate credentials on a schedule, eliminating the need for manual updates. This makes it a correct choice for the question's requirement to manage secrets and database credentials securely.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS CloudFormation
Why it's wrong here
AWS CloudFormation is an infrastructure-as-code service that provisions and manages AWS resources from declarative templates. Although it can reference secrets stored in Secrets Manager or Parameter Store via dynamic references (e.g., {{resolve:secretsmanager:...}}), it does not natively store, rotate, or safeguard secret material. Therefore, it is not a secret management service itself.
- ✓
AWS Secrets Manager
Why this is correct
AWS Secrets Manager is a purpose-built service for centrally managing the entire secret lifecycle, including storing, retrieving, and automatically rotating secrets such as database credentials, API keys, and OAuth tokens. It enforces fine-grained IAM access policies, integrates with AWS KMS for encryption, and supports automatic rotation via AWS Lambda with built-in integrations for RDS, Redshift, and DocumentDB. This makes it the most comprehensive choice for managing secrets.
- ✗
Amazon S3
Why it's wrong here
Amazon S3 is highly durable object storage, but it is not designed for secret management. While objects can be encrypted with SSE-KMS and access can be restricted with bucket policies, S3 lacks native secret rotation, secret versioning tied to lifecycle, and automatic credential revocation. Using S3 for secrets often leads to stale credentials, overly broad access, and no audit trail of secret retrieval, which violates security best practices.
- ✗
AWS Identity and Access Management (IAM)
Why it's wrong here
AWS Identity and Access Management (IAM) governs who can access AWS resources by defining users, groups, roles, and policies, but it does not store application secrets. IAM can issue temporary credentials via AWS STS for API access, yet it cannot hold long-lived values like database passwords or third-party API keys. Thus, IAM is an access-control mechanism, not a secret storage or management service.
- ✓
AWS Systems Manager Parameter Store
Why this is correct
AWS Systems Manager Parameter Store offers a hierarchical, serverless store for configuration data and secrets, allowing encrypted parameters with AWS KMS and IAM-based access control. It is a legitimate secret management option, capable of securely storing passwords and API keys, but it does not natively support automatic rotation for most parameter types. This makes it a simpler, often cheaper alternative to Secrets Manager, though with more manual operational overhead.
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.