AWS Certified Developer – Associate (DVA-C02)SecurityMedium
A developer is building a new serverless application using AWS Lambda and Amazon API Gateway. The application needs to securely store and retrieve sensitive configuration parameters, such as database connection strings and API keys, without hardcoding them into the Lambda function code. The developer wants to ensure that these parameters are encrypted at rest and in transit, and that access is strictly controlled. Which AWS service is the most appropriate for this requirement?
- AAmazon S3
- BAWS Systems Manager Parameter Store
- CAWS DynamoDB
- DAWS Secrets Manager
Show answer & explanationAnswer & explanation
Correct answer: D. AWS Secrets Manager
AWS Secrets Manager is designed specifically for securely storing and managing sensitive information like database credentials, API keys, and other secrets throughout their lifecycle. It offers automatic rotation, fine-grained access control, and integration with other AWS services.
Why the other options are wrong
- A. Amazon S3 is object storage, not ideal for managing frequently accessed application configuration secrets.
- B. AWS Systems Manager Parameter Store can store parameters, but Secrets Manager offers enhanced features specifically for secrets, such as automatic rotation and more robust secret management capabilities.
- C. AWS DynamoDB is a NoSQL database, suitable for structured data storage, but not optimized for managing application secrets.
AWS Secrets Manager
A service that helps you protect access to your applications, services, and IT resources by easily rotating, managing, and retrieving database credentials, API keys, and other secrets throughout their lifecycle.
- Securely stores and encrypts sensitive information.
- Supports automatic rotation of secrets.
- Offers fine-grained access control with IAM.
Memory trick: Secrets Manager keeps your keys safe and rotating.