Courseiva
Design for New Solutions →easyMultiple Choice

SAP-C02 Design for New Solutions Practice Question

A company is designing a new application that requires secure storage of secrets such as database passwords and API keys. The application runs on Amazon EC2 instances. The company wants to centralize secret management and automatically rotate secrets. Which AWS service should be used?

⚠ Common exam trap

SAP-C02 often tests the distinction between KMS (encryption keys), Parameter Store (configuration and basic secrets), and Secrets Manager (managed rotation), so candidates must recognize that automatic rotation is the key differentiator.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Secrets Manager

AWS Secrets Manager is purpose-built for secure secret storage with built-in automatic rotation for RDS, Redshift, and DocumentDB credentials, plus custom Lambda-based rotation for other secrets. It centralizes secret management and integrates natively with EC2 via the AWS SDK or Secrets Manager Agent. KMS is for encryption keys, not secret lifecycle management, and Parameter Store lacks native rotation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Key Management Service (KMS)

    Why it's wrong here

    KMS manages encryption keys, not application secrets; it stores no database passwords or API keys and performs no rotation. KMS is tempting because it is a security service, but Secrets Manager is purpose-built for centralised secret storage with automatic rotation.

  • ✗

    AWS CloudHSM

    Why it's wrong here

    CloudHSM provides dedicated hardware security modules for cryptographic key operations, not a managed secret store with rotation. It is tempting for key custody, but Secrets Manager centralises credentials and rotates them natively; CloudHSM would require custom rotation logic.

  • ✗

    AWS Systems Manager Parameter Store

    Why it's wrong here

    AWS Systems Manager Parameter Store securely centralises the storage of configuration data and secrets, such as database passwords and API keys, aligning with the need for secure and centralised secret management. However, it does not offer native automatic secret rotation, a crucial requirement for this scenario. While Parameter Store is excellent for managing non-rotating parameters or secrets where rotation is handled by custom scripts, it fails to meet the explicit demand for *automatic* rotation.

  • ✓

    AWS Secrets Manager

    Why this is correct

    AWS Secrets Manager stores secrets centrally and natively rotates them on a schedule using Lambda rotation functions, so database passwords and API keys are updated automatically. EC2 instances retrieve secrets at runtime via the API, eliminating hard-coded credentials.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SAP-C02 question is part of Courseiva's 984-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on SAP-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company needs to store configuration data for multiple applications in a centralized, secure, and versioned manner. The configuration must be encrypted at rest and automatically rotated. Which AWS service should they use?

easy
  • A.AWS CloudFormation
  • B.AWS Secrets Manager
  • ✓ C.AWS AppConfig
  • D.AWS Systems Manager Parameter Store

Why C: AWS AppConfig supports versioned configuration, encryption at rest, and automatic rotation. Option A (AWS CloudFormation) is for infrastructure as code, not for storing application configuration. Option B (AWS Secrets Manager) is designed for managing secrets (e.g., passwords, API keys), not general configuration data. Option D (AWS Systems Manager Parameter Store) can store configuration but does not support automatic rotation of configuration values.

Variation 2. A company wants to store configuration data for multiple applications securely. Each application runs on Amazon EC2 instances in an Auto Scaling group. The configuration includes database credentials and API keys. Which TWO services should be used together to achieve this?

easy
  • A.AWS Secrets Manager.
  • B.Amazon S3 with bucket policies.
  • ✓ C.IAM roles for EC2 instances.
  • D.EC2 user data scripts.
  • ✓ E.AWS Systems Manager Parameter Store.

Why C: Option C (IAM roles for EC2 instances) is correct because attaching an IAM role to the EC2 instances (via an instance profile) provides temporary, automatically rotated credentials through the instance metadata service, allowing the applications to call AWS APIs without embedding long-term access keys. Option E (AWS Systems Manager Parameter Store) is correct because it can store configuration data and secrets such as database credentials and API keys as SecureString parameters encrypted with AWS KMS, and applications on the EC2 instances can retrieve them at runtime using the permissions granted by the IAM role. Together, Parameter Store holds the sensitive configuration and the IAM role authorizes secure, keyless retrieval, which fits applications in an Auto Scaling group where instances are ephemeral. Option A (AWS Secrets Manager) is a valid secret-storage service, but it is not one of the two marked answers for this scenario. Option B (Amazon S3 with bucket policies) is not ideal for storing credentials and API keys, since S3 is object storage and bucket policies alone do not provide secret management features like encryption-focused SecureString parameters or managed rotation. Option D (EC2 user data scripts) is unsuitable because user data is visible in instance metadata and is not a secure mechanism for storing or retrieving secrets.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.