AWS Certified Developer – Associate (DVA-C02)Development with AWS ServicesMedium
A developer needs to store sensitive configuration data, such as database credentials and API keys, for an application deployed on AWS. This data should be accessible by EC2 instances and Lambda functions, encrypted at rest, and support versioning for auditing purposes. Which AWS service is BEST suited for this requirement?
- AEnvironment variables in Lambda and EC2 user data
- BAmazon S3
- CAWS Secrets Manager
- DAWS Systems Manager Parameter Store
Show answer & explanationAnswer & explanation
Correct answer: C. AWS Secrets Manager
AWS Secrets Manager is specifically designed for securely storing and managing sensitive information like database credentials and API keys. It provides built-in encryption, automatic rotation, and versioning, which are key requirements for this scenario.
Why the other options are wrong
- A. Environment variables and user data are not secure for sensitive data, lack versioning, and do not offer robust encryption or rotation mechanisms.
- B. S3 can store data, but managing sensitive secrets (rotation, fine-grained access, specific secret types) is not its primary purpose.
- D. Parameter Store can store parameters, including secure strings, but Secrets Manager offers more advanced features like automatic rotation and specific secret types (e.g., database credentials).
AWS Secrets Manager
A service that helps you protect access to your applications, services, and IT resources by easily rotating, managing, and retrieving database credentials, API keys, and other secrets throughout their lifecycle.
- Automates rotation of secrets.
- Integrates with other AWS services (e.g., RDS, Lambda).
- Encrypts secrets at rest and in transit.
- Provides auditing capabilities through AWS CloudTrail.
Memory trick: Secrets need a dedicated manager to rotate and protect them.