Courseiva
Security →easyMultiple Choice

CV0-004 Security Practice Question

A security administrator needs to store database credentials and API keys securely in AWS. The credentials must be automatically rotated every 90 days. Which service should the administrator use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Secrets Manager

AWS Secrets Manager is designed to store secrets and provides built-in rotation capabilities.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Systems Manager Parameter Store

    Why it's wrong here

    Parameter Store holds credentials and API keys, but its automatic rotation requires a Lambda function and applies only to RDS credentials via Secrets Manager integration; standalone API keys are not rotated natively. It is tempting as a secure secret store, and would be correct for static configuration parameters or non-rotating secrets.

  • ✗

    AWS KMS

    Why it's wrong here

    AWS KMS manages encryption keys and performs cryptographic operations; it stores no database credentials or API keys and cannot rotate them on a schedule. It is tempting because KMS secures secrets at rest, and it would be correct for creating and rotating customer master keys that encrypt those secrets.

  • ✓

    AWS Secrets Manager

    Why this is correct

    AWS Secrets Manager natively stores and encrypts secrets, and its built-in rotation schedules Lambda functions to change credentials automatically. This directly satisfies the stem's 90-day rotation requirement, which AWS Systems Manager Parameter Store cannot perform without custom automation.

  • ✗

    AWS Certificate Manager

    Why it's wrong here

    AWS Certificate Manager provisions and renews TLS/SSL certificates for load balancers and CloudFront, not database credentials or API keys, so it cannot rotate them every 90 days. It is tempting because it does perform automatic rotation, but only of certificates, making it correct when securing HTTPS endpoints rather than storing secrets.

About these practice questions

One of 834 original CV0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.