AWS Certified Developer – Associate (DVA-C02)DeploymentEasy

A development team is deploying a new web application that uses an Amazon RDS database. They want to ensure that database credentials are securely managed and rotated automatically without hardcoding them in the application code. Which AWS service should the team use to meet this requirement?

  1. AAWS Key Management Service (KMS)
  2. BAWS Secrets Manager
  3. CAWS Systems Manager Parameter Store
  4. DAmazon Cognito
Show answer & explanation

Correct answer: B. AWS Secrets Manager

AWS Secrets Manager is designed for securely storing and rotating database credentials, API keys, and other secrets. It integrates directly with Amazon RDS for automatic rotation.

Why the other options are wrong

  • A. KMS is used for encrypting data and secrets, but not for storing or managing the lifecycle of the secrets themselves.
  • C. Parameter Store can store secrets but lacks automatic rotation capabilities for database credentials.
  • D. Amazon Cognito is an identity service for managing user authentication and authorization, not for database credentials.

AWS Secrets Manager

A service that helps you protect access to your applications, services, and IT resources. It enables you to easily rotate, manage, and retrieve database credentials, API keys, and other secrets throughout their lifecycle.

  • Securely stores and retrieves secrets.
  • Automates rotation of database credentials.
  • Integrates with RDS, Redshift, DocumentDB.
  • Provides fine-grained access control.

Memory trick: Secrets Manager is the key master for your database keys.

More Deployment questions