AWS Secrets Manager for Secure Credential Storage
Which AWS service or feature allows users to securely store encrypted credentials and retrieve these credentials when required?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The key insight is distinguishing between a secrets management service (Secrets Manager) and encryption tools (Encryption SDK), while recognizing that security hubs and compliance portals do not handle credential storage.
This question tests the identification of AWS Secrets Manager as the service designed to securely store, manage, and retrieve encrypted credentials like database passwords and API keys.
Candidates often confuse AWS Secrets Manager with AWS Encryption SDK, mistakenly believing that raw encryption libraries are the primary tool for managing application secrets in an operational context.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
AWS Secrets Manager is specifically designed for securely storing, retrieving, and rotating secrets such as database credentials, API keys, and other sensitive information. It integrates with IAM for fine-grained access control and supports automatic rotation, making it the ideal solution for the scenario described.Why the Other Options Are Wrong
AWS Encryption SDK (Option A) provides libraries for encrypting data at rest or in transit but does not offer a centralized service for storing and managing secrets. AWS Security Hub (Option B) aggregates security findings and compliance checks but does not store credentials. AWS Artifact (Option D) is used for downloading compliance reports and agreements, not for runtime secret management.Community Comment Notes
Community feedback consistently confirms C as the correct answer. Users like e59311f noted that Secrets Manager allows central management of secrets with IAM policies and rotation support. The consensus highlights its role in handling sensitive information securely.Exam Strategy
When asked about storing or managing secrets, immediately look for 'Secrets Manager' or 'Parameter Store'. Remember that 'Security Hub' is for monitoring, and 'Artifact' is for compliance docs.
Frequently Asked Questions
Why not use AWS Encryption SDK?
The SDK encrypts data but doesn't provide a managed service for storing and rotating secrets.
What does AWS Artifact do?
It provides on-demand access to AWS compliance reports and agreements, not credentials.
Related Analysis
Practice All CLF-C02 Questions
Access 120 questions with complete answers and detailed explanations.
View Full CLF-C02 Practice Test →