AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceMedium

A development team needs to store and automatically rotate database credentials used by an application, without hard-coding them into application code. Which AWS service is purpose-built for this requirement?

  1. AAWS Key Management Service (KMS)
  2. BAWS Systems Manager Parameter Store
  3. CAWS Identity and Access Management (IAM)
  4. DAWS Secrets Manager
Show answer & explanation

Correct answer: D. AWS Secrets Manager

AWS Secrets Manager is designed to securely store, retrieve, and automatically rotate secrets such as database credentials, API keys, and other sensitive configuration data on a schedule.

Why the other options are wrong

  • A. KMS manages encryption keys, not credential storage or rotation.
  • B. Parameter Store can store secrets but does not natively provide automatic rotation for databases without added Lambda automation.
  • C. IAM manages access permissions, not secret storage or rotation.

AWS Secrets Manager

A service for securely storing, retrieving, and automatically rotating secrets such as database credentials and API keys.

  • Built-in automatic rotation for supported databases
  • Integrates with RDS, Redshift, DocumentDB
  • Encrypts secrets using KMS

Memory trick: Secrets Manager 'manages' and rotates your secrets automatically.

More Security and Compliance questions