AWS Certified DevOps Engineer – ProfessionalConfiguration Management and Infrastructure as CodeHard
A company is implementing a new application that will use a shared Amazon RDS database instance. The application is deployed via AWS CodePipeline. The database credentials need to be dynamically retrieved by the application at runtime and rotated regularly without requiring application code changes. The security team mandates that credentials must never be exposed in plaintext in any configuration file or environment variable within the CI/CD pipeline or on the EC2 instances. Which combination of AWS services should be used to meet these requirements?
- AStore credentials in AWS Secrets Manager; configure automatic rotation; retrieve using AWS SDK and IAM roles.
- BEmbed credentials in an encrypted AMI; launch EC2 instances from this AMI.
- CStore credentials in AWS Systems Manager Parameter Store (SecureString); retrieve using `ssm:GetParameters` IAM action.
- DStore credentials as encrypted artifacts in Amazon S3; decrypt with AWS KMS at runtime.
Show answer & explanationAnswer & explanation
Correct answer: A. Store credentials in AWS Secrets Manager; configure automatic rotation; retrieve using AWS SDK and IAM roles.
AWS Secrets Manager is specifically designed for this scenario. It can store credentials, automatically rotate them (including for RDS), and allows applications to retrieve them securely at runtime via the AWS SDK, leveraging IAM roles for access. This avoids hardcoding and plaintext exposure.
Why the other options are wrong
- B. Embedding credentials in an AMI is insecure as they are static and difficult to rotate without rebuilding and redeploying AMIs, violating the rotation and no plaintext exposure requirements.
- C. Parameter Store with SecureString is a good option for storing sensitive data, but it lacks the built-in automatic rotation capabilities for RDS credentials that Secrets Manager provides, which is a key requirement.
- D. Storing credentials as encrypted S3 artifacts and decrypting with KMS is a custom solution that lacks the built-in rotation and simple retrieval mechanisms of Secrets Manager.
Dynamic Secret Retrieval & Rotation
A security practice where applications retrieve sensitive credentials (secrets) at runtime from a dedicated secret management service, which also handles automatic rotation of these secrets.
- Eliminates hardcoded secrets and plaintext exposure.
- Automates credential lifecycle management (rotation).
- Uses IAM for fine-grained access control to secrets.
Memory trick: Secrets Manager rotates the key, secure access for apps, you see.