AWS Certified SysOps Administrator – AssociateSecurity and ComplianceMedium

A company requires that all secrets, such as API keys and database credentials, used by their applications running on EC2 instances are securely stored and automatically rotated. The SysOps administrator needs to implement a solution that integrates with existing applications and minimizes the risk of credentials being exposed. Which AWS service should be used?

  1. AAWS Systems Manager Parameter Store to store secrets as SecureStrings.
  2. BAWS Secrets Manager to store and automatically rotate secrets.
  3. CAWS Key Management Service (KMS) to encrypt and decrypt secrets stored in S3.
  4. DEnvironment variables on EC2 instances for storing secrets and a custom Lambda for rotation.
Show answer & explanation

Correct answer: B. AWS Secrets Manager to store and automatically rotate secrets.

AWS Secrets Manager is specifically designed for managing, retrieving, and rotating secrets. It natively supports automatic rotation of various secret types (e.g., database credentials, API keys) without requiring application code changes to handle the rotation logic. It also integrates with other AWS services and provides robust access control, directly addressing the requirements for secure storage and automatic rotation while minimizing exposure risk.

Why the other options are wrong

  • A. Systems Manager Parameter Store can store secrets as SecureStrings, but it does not offer built-in automatic rotation capabilities for database credentials or API keys, which would require custom implementation.
  • C. KMS encrypts data, but it doesn't provide a secrets management solution with automatic rotation. Storing secrets in S3, even encrypted, requires additional mechanisms for secure retrieval and rotation.
  • D. Storing secrets in environment variables is insecure and does not provide any mechanism for automatic rotation or centralized management, significantly increasing the risk of exposure and operational overhead.

AWS Secrets Manager

AWS Secrets Manager helps you protect access to your applications, services, and IT resources. It enables you to easily rotate, manage, and retrieve database credentials, API keys, and other secrets throughout their lifecycle.

  • Securely stores secrets (credentials, API keys).
  • Automates secret rotation natively.
  • Integrates with AWS services and applications.
  • Provides granular access control.

Memory trick: Secrets Manager: 'S'ecure 'M'anagement 'A'nd 'R'otation.

More Security and Compliance questions