AWS Certified DevOps Engineer – ProfessionalConfiguration Management and Infrastructure as CodeEasy
A development team is deploying a new microservice to AWS using AWS CloudFormation. They need to ensure that database connection strings, API keys, and other sensitive configuration data are securely managed and rotated without being exposed in the CloudFormation templates or application code. The solution must integrate seamlessly with existing AWS services and provide auditability. Which AWS service should the team use to store and retrieve these sensitive parameters?
- AAWS Secrets Manager
- BAWS Systems Manager Parameter Store
- CAWS Config
- DAmazon S3
Show answer & explanationAnswer & explanation
Correct answer: A. AWS Secrets Manager
AWS Secrets Manager is designed for managing, retrieving, and rotating database credentials, API keys, and other secrets throughout their lifecycle. It integrates with CloudFormation and other AWS services for secure secret handling.
Why the other options are wrong
- B. Parameter Store can store sensitive data but lacks built-in automatic rotation and more advanced secret management features compared to Secrets Manager.
- C. AWS Config is a service that enables you to assess, audit, and evaluate the configurations of your AWS resources. It does not store or manage secrets.
- D. Amazon S3 is an object storage service and is not designed for secure, programmatic access and rotation of secrets like database credentials or API keys.
AWS Secrets Manager
A service that helps you protect access to your applications, services, and IT resources. It enables you to easily rotate, manage, and retrieve database credentials, API keys, and other secrets throughout their lifecycle.
- Automates rotation of secrets.
- Integrates with other AWS services (e.g., RDS, Lambda).
- Provides auditing capabilities via AWS CloudTrail.
Memory trick: Secrets Manager safeguards keys, rotating them with ease.