AWS Certified DevOps Engineer – ProfessionalSecurity and ComplianceEasy

A development team is deploying a new microservice to AWS. The microservice needs to access secrets stored in AWS Secrets Manager. The security team has mandated that the microservice's IAM role must adhere to the principle of least privilege and rotate credentials automatically. Which AWS service and configuration should the team use to ensure the microservice can securely retrieve credentials without embedding them directly in the application code?

  1. ARetrieve secrets directly from Secrets Manager using the AWS SDK with an IAM role attached to the EC2 instance or ECS task.
  2. BEmbed secrets in a CloudFormation template and deploy them with the service.
  3. CStore secrets in environment variables and use an EC2 instance profile for access.
  4. DEncrypt secrets using AWS KMS and store them in an S3 bucket, then decrypt at runtime.
Show answer & explanation

Correct answer: A. Retrieve secrets directly from Secrets Manager using the AWS SDK with an IAM role attached to the EC2 instance or ECS task.

Retrieving secrets directly from AWS Secrets Manager using the AWS SDK and an IAM role adheres to the principle of least privilege, avoids embedding credentials, and leverages Secrets Manager's automatic rotation capabilities.

Why the other options are wrong

  • B. Embedding secrets in CloudFormation templates is highly insecure as it exposes credentials in plain text or easily discoverable forms within your infrastructure code.
  • C. Storing secrets in environment variables is less secure and does not leverage Secrets Manager's features like automatic rotation.
  • D. While S3 and KMS can store encrypted data, Secrets Manager is specifically designed for secret management, including rotation, and direct retrieval is more streamlined.

AWS Secrets Manager

A service that helps you protect access to your applications, services, and IT resources by enabling you to easily rotate, manage, and retrieve database credentials, API keys, and other secrets throughout their lifecycle.

  • Stores and manages secrets securely.
  • Offers automatic rotation of credentials.
  • Integrates with other AWS services like IAM and KMS.

Memory trick: Secrets Manager: Your key to secure, rotating credentials, never hardcoded.

More Security and Compliance questions