How to reference a plaintext SSM Parameter Store value in CloudFormation?
A developer is deploying an application in the AWS Cloud by using AWS CloudFormation. The application will connect to an existing Amazon RDS database. The hostname of the RDS database is stored in AWS Systems Manager Parameter Store as a plaintext value. The developer needs to incorporate the database hostname into the CloudFormation template to initialize the application when the stack is created. How should the developer reference the parameter that contains the database hostname?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question hinges on distinguishing between plaintext and SecureString parameters in Parameter Store when using CloudFormation dynamic references.
This question tests the correct use of dynamic references in AWS CloudFormation to retrieve a plaintext value stored in AWS Systems Manager Parameter Store. The community strongly agrees that the ssm dynamic reference is the proper pattern for plaintext parameters, while ssm-secure is reserved for SecureString types.
Candidates often choose the `ssm-secure` dynamic reference (Option D) because they associate Parameter Store with sensitive data, overlooking that the question explicitly states the value is stored as plaintext.
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Understanding Dynamic References in CloudFormation
AWS CloudFormation provides dynamic references to allow templates to include external values without hardcoding them. There are two primary dynamic reference patterns for AWS Systems Manager Parameter Store:
{{resolve:ssm:parameter-name:version}}— used for plaintext parameters (typeStringorStringList).{{resolve:ssm-secure:parameter-name:version}}— used exclusively for SecureString parameters.
Why Option A is Correct
The question explicitly states that the RDS hostname is stored in Parameter Store as a plaintext value. Therefore, the correct approach is to use the ssm dynamic reference pattern. This pattern retrieves the value at stack creation time and injects it into the template without exposing it in the template body.
Why the Other Options are Incorrect
- Option B (
Refintrinsic function): TheReffunction is used to reference parameters declared within the same CloudFormation template or to get the physical ID of a resource created by the stack. It cannot directly retrieve values from Parameter Store unless the parameter is explicitly declared in the template withType: AWS::SSM::Parameter::Value<String>(which is a different mechanism, not what the question asks). - Option C (
Fn::ImportValue): This function retrieves values that were exported from another CloudFormation stack. The question does not mention any cross-stack exports, making this option irrelevant. - Option D (
ssm-securedynamic reference): This pattern is strictly for SecureString parameters. Since the question specifies the value is plaintext, usingssm-securewould result in an error.
Community Consensus
The community overwhelmingly supports Option A (91% of votes). As user DeaconStJohn noted, "As it is the DB hostname and not sensitive credentials I think ssm dynamic is the correct answer. Option D is for secure string whereas this parameter is currently stored in plain text." User preachr also confirmed: "To reference a plaintext value stored in Parameter Store in your template, you use the ssm dynamic reference pattern."
Official Reference
Exam Strategy
When a question mentions Parameter Store, immediately check whether the value is plaintext or SecureString. This distinction determines whether you use ssm or ssm-secure dynamic references—a common trap on the AWS Developer exam.
Related Analysis
Practice All DVA-C02 Questions
Access 100 questions with complete answers and detailed explanations.
View Full DVA-C02 Practice Test →