SAP-C02 Practice Question: Accelerate Workload Migration and Modernization
A company is modernizing a monolithic Java application to run on Amazon ECS with Fargate. The application uses a proprietary configuration management system. Which TWO AWS services can replace the configuration management system to store and retrieve configuration at runtime?
⚠ Common exam trap
SAP-C02 often tests the distinction between configuration management (AppConfig/Parameter Store) and secret management (Secrets Manager) — candidates incorrectly pick Secrets Manager for all runtime configuration needs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS AppConfig, a feature of AWS Systems Manager.
AWS AppConfig (option D) is a feature of AWS Systems Manager designed specifically for application configuration management, allowing you to store, validate, and deploy configuration data with runtime retrieval via the AppConfig API or Lambda extension, making it a direct replacement for a proprietary configuration management system. AWS Systems Manager Parameter Store (option E) provides hierarchical, versioned storage for configuration data and secrets, with runtime retrieval through the SSM API, and is a standard AWS-native configuration store for ECS/Fargate workloads. Option A (Amazon S3 with versioning) is object storage, not a configuration management service, and lacks native runtime configuration retrieval semantics. Option B (AWS Secrets Manager) is purpose-built for secrets such as credentials and API keys, not general application configuration. Option C (Amazon DynamoDB with application-side caching) is a database, not a configuration management service, and would require custom application logic to serve as a configuration store.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon S3 with versioning enabled.
Why it's wrong here
S3 with versioning stores objects and retains object history, but it offers no runtime configuration API for retrieving individual parameters or secrets; the application would need custom code to poll objects. It fits storing artefacts or static files, while AWS AppConfig and Parameter Store deliver configuration to running ECS tasks.
- ✗
AWS Secrets Manager.
Why it's wrong here
Secrets Manager stores and rotates credentials such as database passwords, but it is not designed as a general configuration store for arbitrary application settings, and it lacks AppConfig's feature flags and validation. It is correct when the requirement is secret rotation, whereas Parameter Store and AppConfig cover runtime configuration retrieval.
- ✗
Amazon DynamoDB with application-side caching.
Why it's wrong here
DynamoDB is a key-value database requiring the application to implement its own retrieval, caching and change-detection logic, which does not replace a configuration management system's runtime delivery. It suits storing application data at scale, while AWS AppConfig and Parameter Store provide managed configuration retrieval with validation and deployment strategies.
- ✓
AWS AppConfig, a feature of AWS Systems Manager.
Why this is correct
AWS AppConfig stores configuration externally and delivers it to ECS tasks at runtime through the AppConfig agent or API, with validation and controlled rollout. This replaces the proprietary configuration management system, satisfying the requirement to store and retrieve configuration dynamically without redeploying the Java containers.
- ✓
AWS Systems Manager Parameter Store.
Why this is correct
Parameter Store provides hierarchical, versioned storage with IAM-controlled access and encryption via KMS, letting Fargate tasks fetch configuration at runtime through the AWS SDK or task-definition references. This directly replaces the proprietary configuration system without embedding values in container images.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SAP-C02 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.