SAP-C02 Design for New Solutions Practice Question
A company is designing a new cloud-native application on AWS. The application will use a microservices architecture and requires a way to manage configuration data and secrets. Which THREE AWS services can be used to meet these requirements? (Choose THREE.)
⚠ Common exam trap
SAP-C02 often tests whether candidates can distinguish purpose-built configuration/secrets services from general-purpose storage like S3 or DynamoDB, which lack native rotation and deployment features.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Secrets Manager
AWS Secrets Manager (A) is correct because it is purpose-built to store, rotate, and retrieve secrets such as database credentials and API keys via API calls, which fits managing secrets in a microservices application. AWS Systems Manager Parameter Store (B) is correct because it provides centralized, hierarchical storage for configuration data and secrets, with SecureString parameters encrypted by KMS, and integrates natively with AWS services and applications. AWS AppConfig (C) is correct because it is a feature of Systems Manager designed to create, validate, deploy, and roll back application configuration updates dynamically, which suits managing configuration for microservices. Amazon DynamoDB (D) is not a configuration or secrets management service; it is a NoSQL database, so using it for this purpose would be a custom, non-purpose-built solution. Amazon S3 (E) is object storage and, while it can hold files, it lacks native secret rotation, hierarchical parameter management, and configuration deployment/validation features required here.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS Secrets Manager
Why this is correct
AWS Secrets Manager stores and rotates credentials, API keys and database passwords, directly satisfying the secrets requirement. Its native rotation via Lambda and fine-grained IAM and resource policies suit microservices that must retrieve secrets at runtime rather than embedding them, which the stem's cloud-native constraint demands.
- ✓
AWS Systems Manager Parameter Store
Why this is correct
AWS Systems Manager Parameter Store holds both plain configuration strings and encrypted SecureString secrets, so it satisfies the configuration and secrets requirements in one service. Standard parameters are free, and hierarchical naming with IAM policies lets microservices retrieve only their own values, matching the stem's architecture.
- ✓
AWS AppConfig
Why this is correct
AWS AppConfig supplies dynamic runtime configuration and feature flags for microservices, satisfying the configuration-data requirement. It validates and deploys application configuration separately from code, and integrates with AWS Secrets Manager or Parameter Store for sensitive values, so it covers the configuration half of the stem's dual requirement.
- ✗
Amazon DynamoDB
Why it's wrong here
DynamoDB is a NoSQL database for application data, not a managed configuration or secrets store; it provides no native secret encryption, rotation or hierarchical configuration API. It is tempting because it can hold key-value items, but that is for persistent application state, not secrets management.
- ✗
Amazon S3
Why it's wrong here
Amazon S3 is object storage, not a configuration or secrets management service; it lacks native secret rotation, versioning of secret values or fine-grained secret access APIs. It is tempting because S3 can store encrypted files, but that is for static data, not dynamic application configuration.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SAP-C02 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.