Security, Identity, and Compliance
CoreAWS Secrets Manager
Managed storage, retrieval, and rotation of application credentials.
Key points
- Secrets Manager stores, retrieves, and can rotate database credentials, API keys, and other secrets.
- Workloads should fetch secrets through roles at runtime instead of embedding them in code or images.
Best-known use cases
- Remove database credentials and API keys from pipeline code.
- Retrieve and rotate secrets used by ingestion and transformation jobs.
What candidates often confuse it with
- Secrets Manager is rotation-oriented secret storage; Parameter Store also holds configuration and protected values with a different lifecycle focus.
Key takeaway
Choose Secrets Manager when pipeline credentials need controlled retrieval and regular rotation.
Relevant exam tasks
- D1.2 — Task 1.2: Transform and process data
- 1.2.2 — Connect to different data sources (for example, Java Database Connectivity [JDBC], Open Database Connectivity [ODBC]).
- D4.1 — Task 4.1: Apply authentication mechanisms
- 4.1.3 — Create and rotate credentials for password management (for example, AWS Secrets Manager).
- D4.2 — Task 4.2: Apply authorization mechanisms
- 4.2.2 — Store application and database credentials (for example, Secrets Manager, AWS Systems Manager Parameter Store).