AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceMedium
A development team needs to store and automatically rotate database credentials used by an application, without hard-coding them into application code. Which AWS service is purpose-built for this requirement?
- AAWS Key Management Service (KMS)
- BAWS Systems Manager Parameter Store
- CAWS Identity and Access Management (IAM)
- DAWS Secrets Manager
Show answer & explanationAnswer & explanation
Correct answer: D. AWS Secrets Manager
AWS Secrets Manager is designed to securely store, retrieve, and automatically rotate secrets such as database credentials, API keys, and other sensitive configuration data on a schedule.
Why the other options are wrong
- A. KMS manages encryption keys, not credential storage or rotation.
- B. Parameter Store can store secrets but does not natively provide automatic rotation for databases without added Lambda automation.
- C. IAM manages access permissions, not secret storage or rotation.
AWS Secrets Manager
A service for securely storing, retrieving, and automatically rotating secrets such as database credentials and API keys.
- Built-in automatic rotation for supported databases
- Integrates with RDS, Redshift, DocumentDB
- Encrypts secrets using KMS
Memory trick: Secrets Manager 'manages' and rotates your secrets automatically.