Courseiva
mediumMultiple Select

CCSP Practice Question: A development team builds a serverless…

A development team builds a serverless application using AWS Lambda. The security team wants to prevent hardcoded credentials. Which TWO methods should they enforce for secure secrets management?

⚠ Common exam trap

The trap is that candidates see 'encrypted' or 'third-party manager' and assume security is achieved, missing that the root credential must still be stored securely — hardcoding anything defeats the purpose.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Assign an IAM role to the Lambda function and retrieve temporary credentials via the AWS SDK

Option B is correct because assigning an IAM execution role to the Lambda function lets the AWS SDK obtain temporary credentials from the AWS STS service automatically, eliminating the need to hardcode long-lived access keys in code or configuration. Option E is correct because AWS Systems Manager Parameter Store supports SecureString parameters encrypted with AWS KMS, allowing Lambda to fetch secrets at runtime via the SDK with IAM-controlled access instead of embedding them. Option A is wrong because plain-text environment variables expose credentials in the Lambda console and are not encrypted or rotated. Option C is wrong because embedding secrets in code, even if the code artifact is encrypted, still hardcodes credentials that persist in source control and deployment packages. Option D is wrong because using a third-party secrets manager with a hardcoded API key simply replaces one hardcoded credential with another.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Store secrets in environment variables in plain text

    Why it's wrong here

    Plain-text environment variables expose credentials to anyone with Lambda console or API access, and they appear in logs and CloudFormation templates. AWS Secrets Manager or Systems Manager Parameter Store with encryption is required. Environment variables suit non-sensitive configuration such as feature flags or region names, not secrets.

  • ✓

    Assign an IAM role to the Lambda function and retrieve temporary credentials via the AWS SDK

    Why this is correct

    Attaching an IAM role to the Lambda execution role lets the function call AWS STS for short-lived credentials, so no long-term secret is stored in code or environment variables. This directly satisfies the stem's requirement to prevent hardcoded credentials, since rotation is automatic and credentials expire.

  • ✗

    Embed secrets directly in the Lambda function code but encrypt the code

    Why it's wrong here

    Encrypting code does not remove the credential; the function must still decrypt and use it at runtime, so the secret remains embedded in the deployment package. It is tempting because encryption appears to protect the value, and it would suit protecting data at rest rather than supplying runtime credentials.

  • ✗

    Use a third-party secrets manager with a hardcoded API key in the code

    Why it's wrong here

    A hardcoded API key reintroduces exactly the static credential the team wants eliminated, and rotating it requires redeploying code. It is tempting because third-party secrets managers are a legitimate pattern, but they must be accessed via IAM roles or short-lived tokens, not embedded keys.

  • ✓

    Use AWS Systems Manager Parameter Store with KMS encryption

    Why this is correct

    Parameter Store holds secrets outside the deployment package and KMS encryption protects them at rest, so the Lambda function retrieves values at runtime rather than embedding them. This satisfies the stem's no-hardcoded-credentials constraint, with IAM policies scoping which functions may decrypt each parameter.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.