mediumMultiple Select
CCSP Practice Question: A development team builds a serverless…
A development team builds a serverless application using AWS Lambda. The security team wants to prevent hardcoded credentials. Which TWO methods should they enforce for secure secrets management?
⚠ Common exam trap
The trap is that candidates see 'encrypted' or 'third-party manager' and assume security is achieved, missing that the root credential must still be stored securely — hardcoding anything defeats the purpose.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Assign an IAM role to the Lambda function and retrieve temporary credentials via the AWS SDK
Option B is correct because assigning an IAM execution role to the Lambda function lets the AWS SDK obtain temporary credentials from the AWS STS service automatically, eliminating the need to hardcode long-lived access keys in code or configuration. Option E is correct because AWS Systems Manager Parameter Store supports SecureString parameters encrypted with AWS KMS, allowing Lambda to fetch secrets at runtime via the SDK with IAM-controlled access instead of embedding them. Option A is wrong because plain-text environment variables expose credentials in the Lambda console and are not encrypted or rotated. Option C is wrong because embedding secrets in code, even if the code artifact is encrypted, still hardcodes credentials that persist in source control and deployment packages. Option D is wrong because using a third-party secrets manager with a hardcoded API key simply replaces one hardcoded credential with another.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Store secrets in environment variables in plain text
Why it's wrong here
Plain-text environment variables expose credentials to anyone with Lambda console or API access, and they appear in logs and CloudFormation templates. AWS Secrets Manager or Systems Manager Parameter Store with encryption is required. Environment variables suit non-sensitive configuration such as feature flags or region names, not secrets.
- ✓
Assign an IAM role to the Lambda function and retrieve temporary credentials via the AWS SDK
Why this is correct
Attaching an IAM role to the Lambda execution role lets the function call AWS STS for short-lived credentials, so no long-term secret is stored in code or environment variables. This directly satisfies the stem's requirement to prevent hardcoded credentials, since rotation is automatic and credentials expire.
- ✗
Embed secrets directly in the Lambda function code but encrypt the code
Why it's wrong here
Encrypting code does not remove the credential; the function must still decrypt and use it at runtime, so the secret remains embedded in the deployment package. It is tempting because encryption appears to protect the value, and it would suit protecting data at rest rather than supplying runtime credentials.
- ✗
Use a third-party secrets manager with a hardcoded API key in the code
Why it's wrong here
A hardcoded API key reintroduces exactly the static credential the team wants eliminated, and rotating it requires redeploying code. It is tempting because third-party secrets managers are a legitimate pattern, but they must be accessed via IAM roles or short-lived tokens, not embedded keys.
- ✓
Use AWS Systems Manager Parameter Store with KMS encryption
Why this is correct
Parameter Store holds secrets outside the deployment package and KMS encryption protects them at rest, so the Lambda function retrieves values at runtime rather than embedding them. This satisfies the stem's no-hardcoded-credentials constraint, with IAM policies scoping which functions may decrypt each parameter.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.