Courseiva

CCSP Cloud Application Security Practice Question

A development team is building a cloud application and needs to store API keys and database passwords securely. The team wants to minimize management overhead and ensure automatic rotation of secrets. Which AWS service should they use?

⚠ Common exam trap

The trap here is assuming that Parameter Store provides automatic rotation like Secrets Manager, when it requires custom implementation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Secrets Manager

AWS Secrets Manager is purpose-built for storing and managing secrets, offering automatic rotation for many AWS services and custom rotation via Lambda. This minimizes management overhead and ensures secrets are regularly rotated, reducing the risk of compromise. The team can focus on application development while Secrets Manager handles the lifecycle of secrets securely.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS IAM roles

    Why it's wrong here

    IAM roles provide temporary credentials for AWS services but are not designed to store arbitrary secrets like API keys or database passwords. They cannot store custom secrets or rotate them. Using IAM roles for this purpose would not work, as the team needs a dedicated secret storage service with rotation capabilities.

  • ✗

    AWS Systems Manager Parameter Store

    Why it's wrong here

    Parameter Store can store secrets as SecureString parameters, but it does not provide automatic rotation out of the box. While it is a valid option for storing secrets, the team would need to implement custom rotation logic, increasing management overhead. Thus, it does not fully meet the requirement for automatic rotation with minimal effort.

  • ✗

    Amazon S3 with server-side encryption

    Why it's wrong here

    Amazon S3 is not intended for secret management. Storing secrets in S3 objects, even with encryption, lacks access control granularity, automatic rotation, and audit trails specific to secrets. It would require custom code to retrieve and rotate secrets, adding complexity and risk. Therefore, it is not suitable for this use case.

  • ✓

    AWS Secrets Manager

    Why this is correct

    AWS Secrets Manager is designed to store and manage secrets such as API keys and database passwords. It provides built-in rotation for supported services like RDS, Redshift, and DocumentDB, and allows custom rotation via Lambda. This reduces management overhead and enhances security by automatically rotating secrets, meeting the team's requirements.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.