CLF-C02 exam dumps

CLF-C02 practice question 101 of 342

AWS Certified Cloud Practitioner. Free level, Amazon Web Services. Free question with the correct answer and a full explanation.

CLF-C02 Question 101

Single answer

A company needs to securely store API keys and database credentials for its applications running on AWS. Which AWS service is the MOST appropriate for this purpose?

  1. A

    AWS Secrets Manager

  2. B

    AWS Systems Manager Parameter Store

  3. C

    Amazon S3 with public-read access

  4. D

    AWS Key Management Service (KMS)

Show answer and explanation

Correct answer: A

Explanation

AWS Secrets Manager is the most appropriate service for securely storing and managing application secrets such as API keys and database credentials. It includes features like encryption at rest, fine-grained access control using IAM, and automatic secret rotation, making it well-suited for this use case.

  • A. Correct.

    AWS Secrets Manager is designed specifically for securely storing and managing secrets like API keys, database credentials, and other sensitive information. It also supports automatic secret rotation.

  • B. Incorrect.

    AWS Systems Manager Parameter Store can store configuration data and secrets, but it lacks some advanced features like automatic secret rotation provided by AWS Secrets Manager.

  • C. Incorrect.

    Amazon S3 with public-read access is not intended for storing sensitive credentials. Public-read access would expose sensitive information to anyone on the internet, which is a significant security risk.

  • D. Incorrect.

    AWS Key Management Service (KMS) is used for encrypting and managing cryptographic keys, not for storing credentials or secrets directly.

Timed practice exam

Take a CLF-C02 practice test under exam conditions

65 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam