Courseiva
Design for New Solutions →easyMultiple Select

SAP-C02 Design for New Solutions Practice Question

A company is designing a new cloud-native application on AWS. The application will use a microservices architecture and requires a way to manage configuration data and secrets. Which THREE AWS services can be used to meet these requirements? (Choose THREE.)

⚠ Common exam trap

SAP-C02 often tests whether candidates can distinguish purpose-built configuration/secrets services from general-purpose storage like S3 or DynamoDB, which lack native rotation and deployment features.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Secrets Manager

AWS Secrets Manager (A) is correct because it is purpose-built to store, rotate, and retrieve secrets such as database credentials and API keys via API calls, which fits managing secrets in a microservices application. AWS Systems Manager Parameter Store (B) is correct because it provides centralized, hierarchical storage for configuration data and secrets, with SecureString parameters encrypted by KMS, and integrates natively with AWS services and applications. AWS AppConfig (C) is correct because it is a feature of Systems Manager designed to create, validate, deploy, and roll back application configuration updates dynamically, which suits managing configuration for microservices. Amazon DynamoDB (D) is not a configuration or secrets management service; it is a NoSQL database, so using it for this purpose would be a custom, non-purpose-built solution. Amazon S3 (E) is object storage and, while it can hold files, it lacks native secret rotation, hierarchical parameter management, and configuration deployment/validation features required here.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    AWS Secrets Manager

    Why this is correct

    AWS Secrets Manager stores and rotates credentials, API keys and database passwords, directly satisfying the secrets requirement. Its native rotation via Lambda and fine-grained IAM and resource policies suit microservices that must retrieve secrets at runtime rather than embedding them, which the stem's cloud-native constraint demands.

  • ✓

    AWS Systems Manager Parameter Store

    Why this is correct

    AWS Systems Manager Parameter Store holds both plain configuration strings and encrypted SecureString secrets, so it satisfies the configuration and secrets requirements in one service. Standard parameters are free, and hierarchical naming with IAM policies lets microservices retrieve only their own values, matching the stem's architecture.

  • ✓

    AWS AppConfig

    Why this is correct

    AWS AppConfig supplies dynamic runtime configuration and feature flags for microservices, satisfying the configuration-data requirement. It validates and deploys application configuration separately from code, and integrates with AWS Secrets Manager or Parameter Store for sensitive values, so it covers the configuration half of the stem's dual requirement.

  • ✗

    Amazon DynamoDB

    Why it's wrong here

    DynamoDB is a NoSQL database for application data, not a managed configuration or secrets store; it provides no native secret encryption, rotation or hierarchical configuration API. It is tempting because it can hold key-value items, but that is for persistent application state, not secrets management.

  • ✗

    Amazon S3

    Why it's wrong here

    Amazon S3 is object storage, not a configuration or secrets management service; it lacks native secret rotation, versioning of secret values or fine-grained secret access APIs. It is tempting because S3 can store encrypted files, but that is for static data, not dynamic application configuration.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SAP-C02 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.