CCSP Cloud Application Security Practice Question
A development team is building a cloud application and needs to store API keys and database passwords securely. The team wants to minimize management overhead and ensure automatic rotation of secrets. Which AWS service should they use?
⚠ Common exam trap
The trap here is assuming that Parameter Store provides automatic rotation like Secrets Manager, when it requires custom implementation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Secrets Manager
AWS Secrets Manager is purpose-built for storing and managing secrets, offering automatic rotation for many AWS services and custom rotation via Lambda. This minimizes management overhead and ensures secrets are regularly rotated, reducing the risk of compromise. The team can focus on application development while Secrets Manager handles the lifecycle of secrets securely.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS IAM roles
Why it's wrong here
IAM roles provide temporary credentials for AWS services but are not designed to store arbitrary secrets like API keys or database passwords. They cannot store custom secrets or rotate them. Using IAM roles for this purpose would not work, as the team needs a dedicated secret storage service with rotation capabilities.
- ✗
AWS Systems Manager Parameter Store
Why it's wrong here
Parameter Store can store secrets as SecureString parameters, but it does not provide automatic rotation out of the box. While it is a valid option for storing secrets, the team would need to implement custom rotation logic, increasing management overhead. Thus, it does not fully meet the requirement for automatic rotation with minimal effort.
- ✗
Amazon S3 with server-side encryption
Why it's wrong here
Amazon S3 is not intended for secret management. Storing secrets in S3 objects, even with encryption, lacks access control granularity, automatic rotation, and audit trails specific to secrets. It would require custom code to retrieve and rotate secrets, adding complexity and risk. Therefore, it is not suitable for this use case.
- ✓
AWS Secrets Manager
Why this is correct
AWS Secrets Manager is designed to store and manage secrets such as API keys and database passwords. It provides built-in rotation for supported services like RDS, Redshift, and DocumentDB, and allows custom rotation via Lambda. This reduces management overhead and enhances security by automatically rotating secrets, meeting the team's requirements.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.