SCS-C02 exam dumps

SCS-C02 practice question 402 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 402

Select 3

Your organization uses AWS Secrets Manager to store and rotate database credentials. A developer has accidentally hardcoded the database credentials in an application. To mitigate the associated risk, what steps should you take to ensure the hardcoded credentials are no longer valid and the application uses Secrets Manager moving forward?

  1. A

    Rotate the secret in Secrets Manager to generate new credentials for the database.

  2. B

    Manually update the hardcoded credentials in the application with the new credentials from Secrets Manager.

  3. C

    Update the application to fetch the database credentials dynamically from Secrets Manager using the AWS SDK.

  4. D

    Enable automatic secret rotation in Secrets Manager to ensure credentials are regularly updated.

  5. E

    Revoke the permissions of the IAM role used by the application to access Secrets Manager.

Show answer and explanation

Correct answers: A, C, D

Explanation

To address the risk of hardcoded credentials, you must rotate the existing secret to invalidate the exposed credentials, update the application to fetch credentials dynamically from Secrets Manager, and enable automatic rotation for ongoing security. Manual updates or restricting access to Secrets Manager do not address the root cause or enhance security moving forward.

  • A. Correct.

    Rotating the secret in Secrets Manager ensures that the hardcoded credentials in the application are no longer valid, mitigating the immediate risk.

  • B. Incorrect.

    Manually updating the hardcoded credentials is not a long-term solution as it does not resolve the issue of hardcoding or ensure dynamic credential management.

  • C. Correct.

    Updating the application to fetch credentials dynamically from Secrets Manager is a best practice, ensuring secure and automated retrieval of secrets.

  • D. Correct.

    Enabling automatic secret rotation ensures that credentials are regularly updated and minimizes the risk of credential exposure in the future.

  • E. Incorrect.

    Revoking the IAM role's permissions to access Secrets Manager would prevent the application from retrieving secrets dynamically, which is counterproductive to resolving the issue.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam