SOA-C02 Deployment, Provisioning, and Automation Practice Question
A SysOps administrator needs to automate the deployment of a three-tier web application. The application consists of an Application Load Balancer, a fleet of EC2 instances running a web server, and an Amazon RDS MySQL database. The administrator must ensure that the database credentials are securely stored and automatically rotated. The administrator also needs to version the infrastructure configuration. Which combination of AWS services should the administrator use?
⚠ Common exam trap
SOA-C02 often tests the difference between Parameter Store and Secrets Manager, particularly around automatic rotation, leading candidates to choose Parameter Store for secrets that require rotation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudFormation for infrastructure and AWS Secrets Manager for secrets.
AWS CloudFormation is used to automate infrastructure deployment and version the configuration as code. AWS Secrets Manager securely stores database credentials and provides automatic rotation. Together, they meet the requirements for secure credential management and infrastructure versioning.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS CloudFormation for infrastructure and AWS Systems Manager Parameter Store for secrets.
Why it's wrong here
While CloudFormation correctly handles infrastructure provisioning, Systems Manager Parameter Store is not designed for RDS credential rotation: it stores secure strings but has no native automated rotation capability. You would need a custom Lambda function or manual process to rotate credentials, which defeats the goal of automated deployment and ongoing secret management. Thus the infrastructure side is valid, but the secrets side fails the rotation requirement.
- ✗
AWS OpsWorks for infrastructure and AWS Secrets Manager for secrets.
Why it's wrong here
OpsWorks provides configuration management with Chef or Puppet rather than declarative infrastructure-as-code templating, so it does not give you versioned, reproducible provisioning of cloud resources the way CloudFormation does. Although Secrets Manager is an appropriate service with automatic RDS credential rotation, pairing it with OpsWorks does not meet the requirement for automated deployment of the underlying infrastructure. This option is therefore wrong on the infrastructure side, not the secrets side.
- ✗
AWS CodeCommit for infrastructure versioning and AWS KMS for secrets.
Why it's wrong here
CodeCommit is a managed Git repository for storing source code and templates; it does not deploy infrastructure, so infrastructure versioning alone will not create or update AWS resources. KMS is a key management and encryption service, not a secret storage service—it cannot rotate RDS credentials or store the credentials themselves in a way that applications retrieve on demand. This option misidentifies both the deployment mechanism and the secret-management mechanism.
- ✓
AWS CloudFormation for infrastructure and AWS Secrets Manager for secrets.
Why this is correct
CloudFormation is the correct infrastructure tool because it provisions AWS resources from declarative templates that can be versioned, reviewed, and rolled back, enabling automated and repeatable deployment. Secrets Manager is the correct secrets tool because it natively supports automatic rotation of RDS credentials through a built-in Lambda rotation function, and CloudFormation can securely reference those secrets using dynamic references. Together they satisfy automated deployment and credential rotation in a single operational pipeline.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.