AWS Certified Developer – Associate (DVA-C02)SecurityEasy

A developer is building a new serverless application that uses AWS Lambda functions to process data. This application needs to securely store and retrieve database credentials and API keys. The security team has mandated that secrets must be automatically rotated and audited. Which AWS service should the developer use to meet these requirements?

  1. AAWS Key Management Service (KMS)
  2. BAWS Systems Manager Parameter Store
  3. CAmazon S3
  4. DAWS Secrets Manager
Show answer & explanation

Correct answer: D. AWS Secrets Manager

AWS Secrets Manager is specifically designed for securely storing, managing, and rotating secrets like database credentials and API keys. It integrates with other AWS services and automatically rotates secrets, fulfilling the security team's requirements.

Why the other options are wrong

  • A. KMS is for managing encryption keys, not for storing and rotating application secrets.
  • B. Parameter Store can store secure strings but lacks the automatic rotation and advanced auditing features of Secrets Manager.
  • C. Amazon S3 is object storage and is not designed for secure secret management with automatic rotation.

AWS Secrets Manager

A service that helps you protect access to your applications, services, and IT resources by enabling you to easily rotate, manage, and retrieve database credentials, API keys, and other secrets throughout their lifecycle.

  • Automates secret rotation
  • Integrates with other AWS services
  • Provides auditing capabilities

Memory trick: Secrets Manager safeguards keys with a turning lock.

More Security questions