How to Encrypt and Automatically Rotate Sensitive AWS Credentials per Environment?
A data visualization company wants to strengthen the security of its core applications. The applications are deployed on AWS across its development, staging, pre-production, and production environments. The company needs to encrypt all of its stored sensitive credentials. The sensitive credentials need to be automatically rotated. A version of the sensitive credentials need to be stored for each environment. Which solution will meet these requirements in the MOST operationally efficient way?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question evaluates whether you know that AWS Secrets Manager supports automatic rotation and that each environment needs a separate secret; the trap is confusing Secrets Manager versions (used for rotation) with Parameter Store parameter versions (which are not automatically rotated).
The AWS DVA-C02 exam tests the ability to select the most operationally efficient service for encrypting and rotating sensitive credentials. For per-environment credentials, AWS Secrets Manager is the clear choice because it provides native automatic rotation and per-secret versioning.
Choosing option A incorrectly assumes that Secrets Manager versions can store different credentials for different environments. In reality, versions are used for rotating the same secret, not for managing environment-specific values, making option D the only appropriate choice.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Option D is correct because AWS Secrets Manager is designed to store encrypted secrets and natively supports automatic rotation via custom or built-in Lambda functions. By creating a new secret for each environment (development, staging, pre-production, production), you can apply environment-specific rotation schedules and access policies, ensuring both security and operational efficiency.
Community comment [1] correctly explains that Secrets Manager supports encryption and automatic rotation, and that creating a new secret for each environment allows you to manage credentials independently. These are exactly the requirements stated in the question.
Why the Other Options Are Wrong
Option A is incorrect because Secrets Manager versions are used to store successive rotation values of the same secret, not to store different credentials for multiple environments. It would violate the principle of separation between environments.
Option B is incorrect because AWS Systems Manager Parameter Store parameter versions are not designed for automatic rotation. While you could store environment-specific parameters, you would need to build your own rotation logic, which is not operationally efficient.
Option C is incorrect because storing credentials in environment variables in application code doesn't encrypt them, doesn't support automatic rotation, and violates best practices for secrets management. As comment [4] notes, "C does not make sense" for these requirements.
Community Comment Notes
Most community comments (100% of votes) selected option D, clearly confirming the official answer. Comment [1] provides a concise rationale focusing on encryption and rotation. Comment [4] dismisses option C as unreasonable, and comment [5] simply states "Different credentials," reinforcing the idea that each environment requires a distinct secret. No comments supported any other option, suggesting a strong consensus.
Official Reference
Exam Strategy
When the question mentions 'automatically rotated' and 'store a version for each environment,' immediately think of AWS Secrets Manager, not Parameter Store. Remember that Secrets Manager rotates the value of a secret within that same secret, so to have environment-specific credentials, you must create a separate secret per environment.
Related Analysis
Practice All DVA-C02 Questions
Access 100 questions with complete answers and detailed explanations.
View Full DVA-C02 Practice Test →