SOA-C02 Security and Compliance Practice Question
A SysOps administrator is designing a solution to manage secrets (e.g., database credentials) for a multi-tier application running on EC2 instances. The solution must rotate secrets automatically and provide fine-grained access control. Which TWO services should be used together? (Choose TWO.)
⚠ Common exam trap
SOA-C02 often tests the misconception that Parameter Store and Secrets Manager are interchangeable, when only Secrets Manager provides native automatic rotation for RDS-style credentials.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Secrets Manager
AWS Secrets Manager (C) is correct because it is the service purpose-built for storing and automatically rotating secrets such as database credentials, using built-in rotation via Lambda functions and native integration with services like RDS, Redshift, and DocumentDB. IAM roles for EC2 (E) is correct because attaching an IAM role to the EC2 instances provides temporary credentials through the instance metadata service (IMDS), enabling fine-grained, least-privilege access control via IAM policies that scope which secrets each instance can retrieve, eliminating hard-coded credentials. AWS KMS (A) is not selected because it is an encryption key management service used to encrypt data and secrets, but it does not itself store or rotate secrets. AWS CloudHSM (B) is not selected because it provides dedicated hardware security modules for key operations and compliance use cases, not secret lifecycle management or rotation. AWS Systems Manager Parameter Store (D) is not selected because, although it can store parameters and SecureString values, it lacks native automatic secret rotation, which the scenario explicitly requires.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS KMS
Why it's wrong here
AWS KMS is a managed service that creates and controls customer master keys (CMKs) used for cryptographic encryption and decryption. It focuses on key lifecycle management, not on storing or versioning application secrets such as database passwords. Even if you encrypt a secret with a KMS key, you must separately store the ciphertext and manage its rotation, making KMS an encryption primitive rather than a secrets manager.
- ✗
AWS CloudHSM
Why it's wrong here
AWS CloudHSM provides dedicated hardware security modules for performing cryptographic operations and storing high-assurance keys. It lacks native interfaces for storing arbitrary secret values, versioning them, or scheduling automatic rotation. To use it as a secrets store, you would need to build custom tooling and database tables, and there is no AWS service integration that retrieves secrets directly from CloudHSM.
- ✓
AWS Secrets Manager
Why this is correct
AWS Secrets Manager is purpose-built for securely storing and automatically rotating database credentials, API keys, and other secrets. It supports built-in rotation for Amazon RDS and Redshift, and custom rotation via AWS Lambda for other services. Secrets can be retrieved on demand through the AWS SDK or CLI, with IAM policies controlling access, and versioning ensures application rollback and staged rotation.
- ✗
AWS Systems Manager Parameter Store
Why it's wrong here
Parameter Store offers secure, hierarchical storage for configuration data and secrets, but it does not have native automatic rotation. To rotate a secret stored in Parameter Store, you must build a separate Lambda function or scheduled process to update the value. It also lacks automatic version history for secrets with the same strength as Secrets Manager, and is better suited for configuration items than for frequently rotated credentials.
- ✓
IAM roles for EC2
Why this is correct
Attaching an IAM role to an EC2 instance is a correct and highly secure way to grant it temporary credentials for AWS APIs, eliminating the need to embed long-lived access keys in code or configuration files. The EC2 instance profile fetches temporary credentials via the instance metadata service, which are automatically rotated by AWS. However, this solves only AWS service authentication; it does not store or rotate non-IAM secrets such as third-party database passwords, so it is complementary to a dedicated secrets manager.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.