AWS Secrets Manager for Secure Credential Storage

Answer Correct answer: C — AWS Secrets Manager securely stores, manages, and retrieves encrypted credentials.

Which AWS service or feature allows users to securely store encrypted credentials and retrieve these credentials when required?

  1. AWS Encryption SDK
  2. AWS Security Hub
  3. AWS Secrets Manager Correct Answer
  4. AWS Artifact

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The key insight is distinguishing between a secrets management service (Secrets Manager) and encryption tools (Encryption SDK), while recognizing that security hubs and compliance portals do not handle credential storage.

This question tests the identification of AWS Secrets Manager as the service designed to securely store, manage, and retrieve encrypted credentials like database passwords and API keys.

Candidates often confuse AWS Secrets Manager with AWS Encryption SDK, mistakenly believing that raw encryption libraries are the primary tool for managing application secrets in an operational context.

Community Discussion (3 comments)

ShaiTay 👍 1 Selected: C
AWS Secrets Manager
Meow7 👍 1
C is correct. need discussion on 424 428 429. Thanks.
e59311f 👍 1 Selected: C
The correct answer is C. AWS Secrets Manager. It allows users to securely store and centrally manage secrets such as database credentials, API keys, and other sensitive information. You can use fine-grained AWS Identity and Access Management (IAM) policies to control access to these secrets, and Secrets Manager also supports automatic rotation of secrets to meet security and compliance requirements1. If you need to retrieve a credential from Secrets Manager, you can log into the AWS account, choose Secrets Manager from the Services menu, search for the desired credential, and retrieve its secret value2.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

AWS Secrets Manager is specifically designed for securely storing, retrieving, and rotating secrets such as database credentials, API keys, and other sensitive information. It integrates with IAM for fine-grained access control and supports automatic rotation, making it the ideal solution for the scenario described.

Why the Other Options Are Wrong

AWS Encryption SDK (Option A) provides libraries for encrypting data at rest or in transit but does not offer a centralized service for storing and managing secrets. AWS Security Hub (Option B) aggregates security findings and compliance checks but does not store credentials. AWS Artifact (Option D) is used for downloading compliance reports and agreements, not for runtime secret management.

Community Comment Notes

Community feedback consistently confirms C as the correct answer. Users like e59311f noted that Secrets Manager allows central management of secrets with IAM policies and rotation support. The consensus highlights its role in handling sensitive information securely.

Exam Strategy

When asked about storing or managing secrets, immediately look for 'Secrets Manager' or 'Parameter Store'. Remember that 'Security Hub' is for monitoring, and 'Artifact' is for compliance docs.

Frequently Asked Questions

Why not use AWS Encryption SDK?

The SDK encrypts data but doesn't provide a managed service for storing and rotating secrets.

What does AWS Artifact do?

It provides on-demand access to AWS compliance reports and agreements, not credentials.

More CLF-C02 FAQ →

Related Analysis

Practice All CLF-C02 Questions

Access 120 questions with complete answers and detailed explanations.

View Full CLF-C02 Practice Test →

← Back to CLF-C02 Study Guide