AWS Certified Developer – Associate (DVA-C02)SecurityMedium
A company is developing a new serverless application using AWS Lambda functions. This application needs to retrieve database credentials, API keys, and other sensitive configuration parameters at runtime. The security team insists on a solution that provides centralized storage for secrets, automatic rotation, and fine-grained access control. Which AWS service is BEST suited for this requirement?
- AAWS Systems Manager Parameter Store
- BAWS Secrets Manager
- CEnvironment variables in Lambda
- DAmazon S3
Show answer & explanationAnswer & explanation
Correct answer: B. AWS Secrets Manager
AWS Secrets Manager is specifically designed for managing, retrieving, and rotating database credentials, API keys, and other secrets throughout their lifecycle. It offers automatic rotation and integrates with KMS for encryption and IAM for fine-grained access control, directly addressing all requirements.
Why the other options are wrong
- A. Parameter Store can store secrets, but its rotation capabilities are less comprehensive than Secrets Manager, especially for database credentials.
- C. Environment variables are suitable for non-sensitive configuration, but not for highly sensitive secrets requiring rotation and centralized management.
- D. S3 can store encrypted files, but it lacks built-in features for secret rotation and direct integration for application retrieval of credentials.
AWS Secrets Manager
AWS Secrets Manager helps you protect access to your applications, services, and IT resources. It enables you to easily rotate, manage, and retrieve database credentials, API keys, and other secrets throughout their lifecycle.
- Centralized secret storage and management.
- Automatic rotation of database credentials (e.g., RDS, Redshift).
- Integrates with AWS KMS for encryption at rest.
- Fine-grained access control via IAM.
Memory trick: Secrets Manager: The vault that rotates, keeps, and controls your keys.