CV0-004 Security Practice Question
A security administrator needs to store database credentials and API keys securely in AWS. The credentials must be automatically rotated every 90 days. Which service should the administrator use?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Secrets Manager
AWS Secrets Manager is designed to store secrets and provides built-in rotation capabilities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Systems Manager Parameter Store
Why it's wrong here
Parameter Store holds credentials and API keys, but its automatic rotation requires a Lambda function and applies only to RDS credentials via Secrets Manager integration; standalone API keys are not rotated natively. It is tempting as a secure secret store, and would be correct for static configuration parameters or non-rotating secrets.
- ✗
AWS KMS
Why it's wrong here
AWS KMS manages encryption keys and performs cryptographic operations; it stores no database credentials or API keys and cannot rotate them on a schedule. It is tempting because KMS secures secrets at rest, and it would be correct for creating and rotating customer master keys that encrypt those secrets.
- ✓
AWS Secrets Manager
Why this is correct
AWS Secrets Manager natively stores and encrypts secrets, and its built-in rotation schedules Lambda functions to change credentials automatically. This directly satisfies the stem's 90-day rotation requirement, which AWS Systems Manager Parameter Store cannot perform without custom automation.
- ✗
AWS Certificate Manager
Why it's wrong here
AWS Certificate Manager provisions and renews TLS/SSL certificates for load balancers and CloudFront, not database credentials or API keys, so it cannot rotate them every 90 days. It is tempting because it does perform automatic rotation, but only of certificates, making it correct when securing HTTPS endpoints rather than storing secrets.
Go deeper
Related to this question
About these practice questions
One of 834 original CV0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.