Courseiva
Deployment →easyMultiple Choice

CV0-004 Deployment Practice Question

A cloud engineer is deploying a new application on AWS and needs to ensure that the application's environment variables are securely stored and not exposed in the source code or CloudFormation templates. Which AWS service should be used to store and retrieve these secrets?

⚠ Common exam trap

The trap here is thinking that CloudFormation NoEcho or Parameter Store String type provides secure secret storage, when they either only hide values or store them unencrypted.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Secrets Manager

AWS Secrets Manager is the appropriate service for securely storing and retrieving secrets like environment variables. It encrypts secrets at rest, supports automatic rotation, and integrates with IAM for access control. Other options either store plaintext, only mask values, or lack secret management features, making them unsuitable for secure secret storage.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Systems Manager Parameter Store (String type)

    Why it's wrong here

    Parameter Store String type stores plaintext values, which are not encrypted and can be viewed by anyone with access to the parameter. While Parameter Store SecureString encrypts values, the question specifically asks for secure storage of environment variables; Secrets Manager is purpose-built for secrets and offers rotation, making it more suitable than plain String parameters.

  • ✓

    AWS Secrets Manager

    Why this is correct

    AWS Secrets Manager is designed to securely store and manage secrets such as database credentials, API keys, and environment variables. It provides encryption at rest using KMS, automatic rotation, and fine-grained access control via IAM. Applications can retrieve secrets at runtime using the AWS SDK, keeping them out of source code and templates, which meets the requirement.

  • ✗

    AWS CloudFormation parameters with the NoEcho attribute

    Why it's wrong here

    CloudFormation NoEcho masks parameter values in the console and API responses, but the values are still stored in the template or passed as plaintext during stack operations. They are not encrypted at rest and can be exposed in logs or stack events. NoEcho is not a secure secret storage solution; it only prevents display.

  • ✗

    Amazon S3 bucket with default encryption

    Why it's wrong here

    Storing secrets in an S3 object, even with default encryption, requires managing access policies and does not provide automatic rotation or fine-grained auditing. It is not a dedicated secret management service, and retrieving secrets from S3 adds complexity. S3 is better for static files, not for dynamic secret storage.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 834 original CV0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.