Secrets Manager stores and rotates sensitive credentials — database passwords, API keys, tokens — so they never live in your code or config files. Apps fetch them at runtime via an API call.

Secrets Manager vs Parameter Store

Both store secrets, but Secrets Manager adds built-in automatic rotation (e.g., rotating an RDS password on a schedule) — the tell on the exam. SSM Parameter Store is cheaper and fine for config values and simple secrets without automatic rotation. Scenario needs automatic credential rotation? Secrets Manager.

Test yourself

Practice question

An application needs its RDS database password stored securely and rotated automatically every 30 days without code changes. Which service?

  1. AWS Secrets Manager
  2. Hard-coded config file
  3. SSM Parameter Store (standard)
  4. An S3 bucket
👉 Click to reveal the answer & explanation

Correct answer: A. Secrets Manager stores credentials and rotates them automatically on a schedule — exactly the requirement. A config file (B) is insecure; standard Parameter Store (C) lacks built-in rotation; an S3 bucket (D) isn’t a secrets store.

Related topics

AWS KMS · AWS IAM · Systems Manager

CloudExamPro Premium

Ready to pass the AWS Solutions Architect Associate (SAA-C03)?

Stop guessing whether you’re ready. Our full-length, exam-realistic practice exams put you through the exact question style you’ll face — with a detailed explanation behind every answer, so you learn why, not just what.

  • ✓  6 full-length practice exams
  • ✓  A detailed explanation for every single question
  • ✓  Realistic, scenario-based questions — not memory dumps
  • ✓  Lifetime access, kept current for 2026

Get the SAA-C03 Practice Exams →or try 25 free questions first

Limited-time offer · ends in --Days:--Hrs:--Min:--Sec
Get Instant Access