How to reference a plaintext SSM Parameter Store value in CloudFormation?

A developer is deploying an application in the AWS Cloud by using AWS CloudFormation. The application will connect to an existing Amazon RDS database. The hostname of the RDS database is stored in AWS Systems Manager Parameter Store as a plaintext value. The developer needs to incorporate the database hostname into the CloudFormation template to initialize the application when the stack is created. How should the developer reference the parameter that contains the database hostname?

  1. Use the ssm dynamic reference. Source Reference Answer
  2. Use the Ref intrinsic function.
  3. Use the Fn::ImportValue intrinsic function.
  4. Use the ssm-secure dynamic reference.

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question hinges on distinguishing between plaintext and SecureString parameters in Parameter Store when using CloudFormation dynamic references.

This question tests the correct use of dynamic references in AWS CloudFormation to retrieve a plaintext value stored in AWS Systems Manager Parameter Store. The community strongly agrees that the ssm dynamic reference is the proper pattern for plaintext parameters, while ssm-secure is reserved for SecureString types.

Candidates often choose the `ssm-secure` dynamic reference (Option D) because they associate Parameter Store with sensitive data, overlooking that the question explicitly states the value is stored as plaintext.

Community Discussion (7 comments)

DeaconStJohn 👍 6 Selected: A
As it is the DB hostname and not sensitive credentials I think ssm dynamic is the correct answer. Option D - is for secure string whereas this parameter is currently stored in plain text. For option C, I opted against this because for an import value, I believe there needs to be an export value from another template. The question didn't state that anything else was created via CF template. Option B - I understand to be used to reference another resource block that is in the same YAML template.
teban0130 👍 1 Selected: A
Parameters: Environment: Type: AWS::SSM::Parameter::Value<String> Default: env
preachr 👍 1 Selected: A
To reference a plaintext value stored in Parameter Store in your template, you use the ssm dynamic reference pattern. This pattern allows you to reference values from parameters of type String or StringList in Parameter Store.
Anandesh 👍 1 Selected: A
https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/dynamic-references.html
65703c1 👍 1 Selected: A
A is the correct answer.
be1dca8 👍 3
A since the question stated that the value is just plain text, not a secureString type
KarBiswa 👍 1 Selected: D
https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/dynamic-references.html#dynamic-references-ssm-secure-strings

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Understanding Dynamic References in CloudFormation

AWS CloudFormation provides dynamic references to allow templates to include external values without hardcoding them. There are two primary dynamic reference patterns for AWS Systems Manager Parameter Store:

  • {{resolve:ssm:parameter-name:version}} — used for plaintext parameters (type String or StringList).
  • {{resolve:ssm-secure:parameter-name:version}} — used exclusively for SecureString parameters.

Why Option A is Correct

The question explicitly states that the RDS hostname is stored in Parameter Store as a plaintext value. Therefore, the correct approach is to use the ssm dynamic reference pattern. This pattern retrieves the value at stack creation time and injects it into the template without exposing it in the template body.

Why the Other Options are Incorrect

  • Option B (Ref intrinsic function): The Ref function is used to reference parameters declared within the same CloudFormation template or to get the physical ID of a resource created by the stack. It cannot directly retrieve values from Parameter Store unless the parameter is explicitly declared in the template with Type: AWS::SSM::Parameter::Value<String> (which is a different mechanism, not what the question asks).
  • Option C (Fn::ImportValue): This function retrieves values that were exported from another CloudFormation stack. The question does not mention any cross-stack exports, making this option irrelevant.
  • Option D (ssm-secure dynamic reference): This pattern is strictly for SecureString parameters. Since the question specifies the value is plaintext, using ssm-secure would result in an error.

Community Consensus

The community overwhelmingly supports Option A (91% of votes). As user DeaconStJohn noted, "As it is the DB hostname and not sensitive credentials I think ssm dynamic is the correct answer. Option D is for secure string whereas this parameter is currently stored in plain text." User preachr also confirmed: "To reference a plaintext value stored in Parameter Store in your template, you use the ssm dynamic reference pattern."

Official Reference

Exam Strategy

When a question mentions Parameter Store, immediately check whether the value is plaintext or SecureString. This distinction determines whether you use ssm or ssm-secure dynamic references—a common trap on the AWS Developer exam.

Related Analysis

Practice All DVA-C02 Questions

Access 100 questions with complete answers and detailed explanations.

View Full DVA-C02 Practice Test →

← Back to DVA-C02 Study Guide