Secrets Manager stores and rotates sensitive credentials — database passwords, API keys, tokens — so they never live in your code or config files. Apps fetch them at runtime via an API call.
Secrets Manager vs Parameter Store
Both store secrets, but Secrets Manager adds built-in automatic rotation (e.g., rotating an RDS password on a schedule) — the tell on the exam. SSM Parameter Store is cheaper and fine for config values and simple secrets without automatic rotation. Scenario needs automatic credential rotation? Secrets Manager.
Test yourself
An application needs its RDS database password stored securely and rotated automatically every 30 days without code changes. Which service?
- AWS Secrets Manager
- Hard-coded config file
- SSM Parameter Store (standard)
- An S3 bucket
👉 Click to reveal the answer & explanation
Correct answer: A. Secrets Manager stores credentials and rotates them automatically on a schedule — exactly the requirement. A config file (B) is insecure; standard Parameter Store (C) lacks built-in rotation; an S3 bucket (D) isn’t a secrets store.
Related topics
AWS KMS · AWS IAM · Systems Manager
Ready to pass the AWS Solutions Architect Associate (SAA-C03)?
Stop guessing whether you’re ready. Our full-length, exam-realistic practice exams put you through the exact question style you’ll face — with a detailed explanation behind every answer, so you learn why, not just what.
- ✓ 6 full-length practice exams
- ✓ A detailed explanation for every single question
- ✓ Realistic, scenario-based questions — not memory dumps
- ✓ Lifetime access, kept current for 2026
Get the SAA-C03 Practice Exams →or try 25 free questions first