Courseiva
Design for New Solutions →hardMultiple Select

SAP-C02 Design for New Solutions Practice Question

A company is designing a new containerized application on Amazon EKS. The application must be able to access secrets (e.g., database credentials) securely. The company requires that secrets be automatically rotated and audited. Which THREE actions should the company take to meet these requirements?

⚠ Common exam trap

A common mix-up: candidates think mounting the CSI driver without ASCP (Option A) is sufficient, but ASCP is the critical component that bridges the CSI driver to AWS Secrets Manager, and without it, the driver cannot retrieve secrets from AWS.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use IAM roles for service accounts (IRSA) to grant pods access to Secrets Manager

Option B is correct because IAM roles for service accounts (IRSA) associates a Kubernetes service account with an IAM role via the cluster's OIDC provider, giving pods scoped, credential-free access to AWS Secrets Manager without embedding long-lived keys. Option C is correct because AWS Secrets Manager natively supports automatic rotation through Lambda rotation functions, and it logs API calls to CloudTrail for auditing, satisfying both the rotation and audit requirements. Option D is correct because the AWS Secrets and Configuration Provider (ASCP) for the Secrets Store CSI Driver mounts Secrets Manager secrets as volumes into pods and can sync them to Kubernetes Secrets, enabling rotation-aware secret delivery to the application. Option A is wrong because the Secrets Store CSI Driver alone cannot retrieve AWS Secrets Manager secrets without the ASCP provider plugin, so mounting the volume directly would fail. Option E is wrong because Kubernetes Secrets are not automatically rotated and are only base64-encoded by default, and ConfigMaps are not designed for sensitive credential storage or auditing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Mount the Secrets Store CSI Driver volume directly to the pod without using ASCP

    Why it's wrong here

    Without ASCP, the CSI driver retrieves secrets but cannot sync them into native Kubernetes Secrets, so rotation is not propagated and pod restarts are needed. ASCP is what enables automatic rotation and audit via CloudTrail. Mounting the volume alone suits static, non-rotating secrets.

  • ✓

    Use IAM roles for service accounts (IRSA) to grant pods access to Secrets Manager

    Why this is correct

    IRSA maps a Kubernetes service account to an IAM role via the EKS OIDC provider, letting pods retrieve Secrets Manager values without long-lived credentials. This enables fine-grained IAM policies and CloudTrail auditing of each secret access.

  • ✓

    Store secrets in AWS Secrets Manager and enable automatic rotation

    Why this is correct

    Secrets Manager provides native automatic rotation via Lambda functions and CloudTrail auditing of secret access, directly satisfying the rotation and audit requirements. Storing credentials here rather than in Kubernetes Secrets or environment variables keeps them centralised and versioned.

  • ✓

    Use the AWS Secrets and Configuration Provider (ASCP) for the Secrets Store CSI Driver to inject secrets into pods

    Why this is correct

    ASCP mounts Secrets Manager secrets as files inside pods via the Secrets Store CSI Driver, so containers read credentials without hardcoding them. This satisfies secure access on EKS while preserving rotation, since the mounted values refresh from Secrets Manager.

  • ✗

    Store secrets in Kubernetes Secrets and use a ConfigMap to reference them

    Why it's wrong here

    Kubernetes Secrets are base64-encoded, not encrypted by default, and ConfigMaps cannot reference them; neither provides automatic rotation or audit trails. It is tempting because Secrets are the built-in mechanism, but AWS Secrets Manager with the Secrets Store CSI driver satisfies the rotation and auditing requirements.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SAP-C02 question is part of Courseiva's 984-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.