How to Encrypt and Automatically Rotate Sensitive AWS Credentials per Environment?

AWS Security – Secrets Management

A data visualization company wants to strengthen the security of its core applications. The applications are deployed on AWS across its development, staging, pre-production, and production environments. The company needs to encrypt all of its stored sensitive credentials. The sensitive credentials need to be automatically rotated. A version of the sensitive credentials need to be stored for each environment. Which solution will meet these requirements in the MOST operationally efficient way?

  1. Configure AWS Secrets Manager versions to store different copies of the same credentials across multiple environments.
  2. Create a new parameter version in AWS Systems Manager Parameter Store for each environment. Store the environment-specific credentials in the parameter version.
  3. Configure the environment variables in the application code. Use different names for each environment type.
  4. Configure AWS Secrets Manager to create a new secret for each environment type. Store the environment-specific credentials in the secret. Source Reference Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question evaluates whether you know that AWS Secrets Manager supports automatic rotation and that each environment needs a separate secret; the trap is confusing Secrets Manager versions (used for rotation) with Parameter Store parameter versions (which are not automatically rotated).

The AWS DVA-C02 exam tests the ability to select the most operationally efficient service for encrypting and rotating sensitive credentials. For per-environment credentials, AWS Secrets Manager is the clear choice because it provides native automatic rotation and per-secret versioning.

Choosing option A incorrectly assumes that Secrets Manager versions can store different credentials for different environments. In reality, versions are used for rotating the same secret, not for managing environment-specific values, making option D the only appropriate choice.

Community Discussion (6 comments)

65703c1 👍 2 Selected: D
D is the correct answer.
keensolution 👍 1
A comprehensive guide to help you navigate the landscape and find the perfect <a href="https://keensolution.in/data-visualization-services/">data visualization agencies in India</a> for your business
SerialiDr 👍 3 Selected: D
D. Configure AWS Secrets Manager to create a new secret for each environment type. Store the environment-specific credentials in the secret. AWS Secrets Manager supports the encryption of secrets (including sensitive credentials) and allows for automatic rotation of these secrets. By creating a new secret for each environment (development, staging, pre-production, and production), you can manage and access the environment-specific credentials securely. This approach facilitates operational efficiency by leveraging AWS Secrets Manager's built-in capabilities for encryption and rotation, without the need for manual intervention or complex configurations. Secrets Manager also provides a straightforward way to retrieve the correct version of the credentials for each specific environment, simplifying the management of sensitive data across different stages of application deployment.
KarBiswa 👍 1 Selected: D
Different credentials
monishvster 👍 1 Selected: D
Should be D
CrescentShared 👍 2 Selected: D
C does not make sense.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Option D is correct because AWS Secrets Manager is designed to store encrypted secrets and natively supports automatic rotation via custom or built-in Lambda functions. By creating a new secret for each environment (development, staging, pre-production, production), you can apply environment-specific rotation schedules and access policies, ensuring both security and operational efficiency.

Community comment [1] correctly explains that Secrets Manager supports encryption and automatic rotation, and that creating a new secret for each environment allows you to manage credentials independently. These are exactly the requirements stated in the question.

Why the Other Options Are Wrong

Option A is incorrect because Secrets Manager versions are used to store successive rotation values of the same secret, not to store different credentials for multiple environments. It would violate the principle of separation between environments.

Option B is incorrect because AWS Systems Manager Parameter Store parameter versions are not designed for automatic rotation. While you could store environment-specific parameters, you would need to build your own rotation logic, which is not operationally efficient.

Option C is incorrect because storing credentials in environment variables in application code doesn't encrypt them, doesn't support automatic rotation, and violates best practices for secrets management. As comment [4] notes, "C does not make sense" for these requirements.

Community Comment Notes

Most community comments (100% of votes) selected option D, clearly confirming the official answer. Comment [1] provides a concise rationale focusing on encryption and rotation. Comment [4] dismisses option C as unreasonable, and comment [5] simply states "Different credentials," reinforcing the idea that each environment requires a distinct secret. No comments supported any other option, suggesting a strong consensus.

Official Reference

Exam Strategy

When the question mentions 'automatically rotated' and 'store a version for each environment,' immediately think of AWS Secrets Manager, not Parameter Store. Remember that Secrets Manager rotates the value of a secret within that same secret, so to have environment-specific credentials, you must create a separate secret per environment.

Related Analysis

Practice All DVA-C02 Questions

Access 100 questions with complete answers and detailed explanations.

View Full DVA-C02 Practice Test →

← Back to DVA-C02 Study Guide