AWS Certified Solutions Architect – Associate (SAA-C03)Design Secure ArchitecturesMedium

A company is developing a new serverless application using AWS Lambda and Amazon DynamoDB. The application needs to securely store API keys for third-party services. These keys must be encrypted and rotated periodically without requiring code changes or redeployments. Which AWS service should be used to manage these API keys?

  1. AAWS Systems Manager Parameter Store
  2. BEnvironment variables in Lambda functions
  3. CAmazon S3 with SSE-KMS
  4. DAWS Secrets Manager
Show answer & explanation

Correct answer: D. AWS Secrets Manager

AWS Secrets Manager is specifically designed for securely storing, retrieving, and rotating secrets like API keys, database credentials, and other sensitive data. It integrates with Lambda and supports automatic rotation, meeting all specified requirements.

Why the other options are wrong

  • A. Parameter Store can store sensitive data (SecureString type), but it does not natively support automatic rotation of secrets, which is a key requirement.
  • B. Environment variables are not encrypted at rest by default and do not support automatic rotation, making them unsuitable for sensitive API keys in a production environment, especially with the rotation requirement.
  • C. Storing API keys in S3, even with SSE-KMS, is not the most secure or manageable solution for application secrets. It lacks features like automatic rotation and direct integration for secret retrieval.

AWS Secrets Manager

A service that helps you securely store, manage, and retrieve secrets, such as database credentials, API keys, and other sensitive data, with optional automatic rotation.

  • Securely stores and retrieves secrets.
  • Supports automatic rotation of secrets.
  • Integrates with AWS services like Lambda.
  • Encrypts secrets at rest and in transit.

Memory trick: Secrets Manager: Securely Store, Rotate, and Retrieve.

More Design Secure Architectures questions