SCS-C02 Data Protection Practice Question
A company needs to securely store database credentials for a legacy application running on Amazon EC2. The credentials are currently hardcoded in the application code. Which service should be used to rotate and retrieve secrets automatically?
⚠ Common exam trap
SCS-C02 often tests the distinction between Secrets Manager and Parameter Store, where candidates incorrectly assume Parameter Store's SecureString provides automatic rotation, but only Secrets Manager offers native rotation for database credentials.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Secrets Manager.
AWS Secrets Manager is purpose-built for storing, rotating, and retrieving secrets such as database credentials. It natively supports automatic rotation via Lambda functions and provides fine-grained access control using IAM and KMS. The legacy application can retrieve credentials programmatically using the Secrets Manager API or SDK, eliminating hardcoded credentials.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Systems Manager Parameter Store with a SecureString parameter.
Why it's wrong here
AWS Systems Manager Parameter Store can store secrets as SecureString parameters encrypted with AWS KMS, but it does not natively support automatic rotation of database credentials. Because the requirement demonstrates a need for lifetime management and scheduled secret rotation, Parameter Store would require building custom Lambda-based automation and versioning logic to match Secrets Manager's built-in behavior.
- ✗
AWS Key Management Service (KMS).
Why it's wrong here
AWS Key Management Service (KMS) is a cryptographic key management service that creates and controls encryption keys, but it has no API for storing or retrieving arbitrary secrets such as database credentials. A secret like a username and password must be encrypted and persisted somewhere else, so KMS by itself cannot satisfy the requirement to securely store the credential.
- ✓
AWS Secrets Manager.
Why this is correct
AWS Secrets Manager is purpose-built for this scenario, offering secure storage, fine-grained access policies, and automatic credential rotation via built-in integrations with services like Amazon RDS and Redshift. It also natively supports secret versioning and schedule-based rotation using Lambda, so database credentials can be refreshed without application downtime or manual intervention.
- ✗
AWS CloudHSM.
Why it's wrong here
AWS CloudHSM provides dedicated hardware security modules in the cloud, allowing you to manage cryptographic keys in FIPS 140-2 validated hardware, but it does not store application credentials like database usernames or passwords. CloudHSM exposes low-level PKCS#11, JCE, or KMS APIs for key operations, not a secret storage and retrieval API, so it cannot serve as the database credential store in this architecture.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.