AWS Certified Solutions Architect – Associate (SAA-C03)Design Secure ArchitecturesMedium

A startup is deploying a new serverless application that uses AWS Lambda functions, Amazon API Gateway, and Amazon DynamoDB. The application needs to store and retrieve API keys, database credentials, and other sensitive configuration parameters. These secrets must be rotated automatically and securely, and access to them should be restricted to only the necessary Lambda functions. Which AWS service is purpose-built to manage these requirements?

  1. AAWS Key Management Service (KMS)
  2. BAWS Systems Manager Parameter Store
  3. CAmazon S3
  4. DAWS Secrets Manager
Show answer & explanation

Correct answer: D. AWS Secrets Manager

AWS Secrets Manager is specifically designed for securely storing, managing, and retrieving secrets such as API keys, database credentials, and other sensitive data. It offers automatic rotation, fine-grained access control, and integration with other AWS services, making it the ideal choice for this scenario.

Why the other options are wrong

  • A. AWS KMS is used for managing encryption keys, not for storing and rotating application secrets themselves, although Secrets Manager uses KMS for encryption.
  • B. Systems Manager Parameter Store can store sensitive data, but it lacks built-in automatic rotation capabilities for secrets like database credentials, which is a key requirement.
  • C. Amazon S3 can store data, but it is not designed for secure secret management with features like automatic rotation, fine-grained access to secrets, and integration with applications for retrieval.

AWS Secrets Manager

AWS Secrets Manager helps you protect access to your applications, services, and IT resources by enabling you to easily rotate, manage, and retrieve database credentials, API keys, and other secrets throughout their lifecycle.

  • Automates rotation of secrets (e.g., database credentials).
  • Provides fine-grained access control through IAM.
  • Integrates with other AWS services (e.g., Lambda, RDS).

Memory trick: Secrets Manager: Rotate, Retrieve, Restrict, Repeat.

More Design Secure Architectures questions