What the exam asks
- Move database passwords and API tokens out of code, and rotate them automatically.
- Choose between Secrets Manager and Parameter Store based on rotation, replication, cross-account access and cost.
- Replace access keys with IAM roles for EC2, ECS, Lambda and on-premises servers.
- Choose Cognito user pools, identity pools or both for customer-facing apps.
- Protect API Gateway APIs and ALB-hosted web apps with the least custom code.
Core ideas
Secrets Manager versus Parameter Store
| AWS Secrets Manager | Systems Manager Parameter Store | |
|---|---|---|
| Built for | Secrets that must rotate (database passwords, API keys) | Configuration data and simple secrets |
| Rotation | Built in: managed rotation for RDS, Aurora, Redshift and DocumentDB, and Lambda rotation functions for anything else | None built in |
| Encryption | Always KMS | SecureString uses KMS; String is plaintext |
| Cross-Region | Replica secrets kept in sync | No native replication |
| Cross-account | Resource-based policy plus a customer managed KMS key | Not the usual exam answer |
| Size | Up to 64 KB | 4 KB (standard) or 8 KB (advanced) |
| Cost | Per secret per month, plus API calls | Standard parameters at no extra charge; advanced parameters are charged |
Decision rule: “rotate automatically” ⇒ Secrets Manager. “Cheapest store for configuration or for secrets that don’t rotate” ⇒ Parameter Store. For RDS and Aurora, the simplest answer is to let the database manage its master user password in Secrets Manager, which takes care of rotation.
You can consume secrets without code changes: