Skip to content
BytePatterns

DVA-C02 · Domain 2: Security · 26% of the exam

Task 2.3: Manage sensitive data in application code

Secrets and personal data inside the application: classifying PII and PHI, encrypted environment variables, Secrets Manager and Parameter Store instead of hard-coded values, masking data before it reaches logs, and keeping each tenant's data apart.

Study it

  • Secrets Manager and Parameter Store from code

    Lesson coming

  • Classifying, masking and sanitizing sensitive data

    Lesson coming

  • Multi-tenant data access

    Lesson coming

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 1

An AWS Lambda function connects to an Amazon RDS for PostgreSQL database with a password stored in a plain environment variable. A security review requires the password to change automatically every 30 days without redeploying the function, and the function must not call a secrets API on every invocation. What should the developer do?

  1. AStore the password as a SecureString parameter and change it with a scheduled script
  2. BSecrets Manager with rotation, read through the Lambda extension's cache
  3. CEncrypt the environment variable with a customer managed key that rotates every 30 days
  4. DPut the password in the deployment package and redeploy the function every 30 days
Show the answer and why
  • AStore the password as a SecureString parameter and change it with a scheduled script

    Incorrect

    Parameter Store has no credential rotation. The script would also have to change the password in the database, which is the work rotation does for you.

  • BSecrets Manager with rotation, read through the Lambda extension's cache

    Correct

    Secrets Manager rotates the secret in both the secret and the database on a schedule, and the extension retrieves and caches the secret so the function does not call the API each time.

  • CEncrypt the environment variable with a customer managed key that rotates every 30 days

    Incorrect

    Rotating the KMS key changes the key that protects the variable. The database password itself stays the same.

  • DPut the password in the deployment package and redeploy the function every 30 days

    Incorrect

    Hard-coded credentials require redeploying for every change, which is what Secrets Manager's runtime retrieval and rotation avoid.

Rotation belongs to Secrets Manager; caching through the Lambda extension keeps per-invocation API calls down.

Question 2 · choose 1

An order service running on Amazon ECS and two AWS Lambda functions share about 40 small configuration values per environment, such as feature switches and service endpoints. One endpoint value must be encrypted at rest. No value needs rotation. The developer wants names like /prod/orders/..., IAM permissions per path, and the lowest cost. What should the developer use?

  1. AOne AWS Secrets Manager secret for each configuration value
  2. BEnvironment variables on each function and task, encrypted with a customer managed key
  3. CAdvanced-tier parameters with a parameter policy on every value
  4. DStandard parameters under /prod/orders/, with a SecureString endpoint
Show the answer and why
  • AOne AWS Secrets Manager secret for each configuration value

    Incorrect

    Secrets Manager charges per secret per month and is built for credentials that need rotation, which none of these values do.

  • BEnvironment variables on each function and task, encrypted with a customer managed key

    Incorrect

    A Lambda function's environment variables are limited to 4 KB in total, and each copy belongs to one function or task, so there is no shared hierarchy to grant access to by path.

  • CAdvanced-tier parameters with a parameter policy on every value

    Incorrect

    The advanced tier is charged per parameter and per API interaction. Values this small fit the standard tier, which has no additional charge.

  • DStandard parameters under /prod/orders/, with a SecureString endpoint

    Correct

    Parameter Store offers hierarchical names that IAM policies can target by path, SecureString encryption with AWS KMS, and standard parameters at no additional charge.

Static configuration goes in Parameter Store (SecureString when it must be encrypted); Secrets Manager is for secrets that need rotation.

Question 3 · choose 1

An AWS Lambda function reads a partner API token from an environment variable. A new rule says the console must show the token only as ciphertext, even to the administrators who manage the function and its KMS key settings, and only the function code may turn it into plaintext at runtime. The team accepts adding decryption code to the function. What should the developer do?

  1. AEncryption helpers with a customer managed key, and decryption in code
  2. BKeep Lambda's default encryption at rest with the AWS managed key
  3. CUse a customer managed key for encryption at rest, with no other change
  4. DMove the token from the variable into the function code as a constant
Show the answer and why
  • AEncryption helpers with a customer managed key, and decryption in code

    Correct

    The helpers encrypt the value client-side, so it is stored and shown as ciphertext. The function decrypts it with kms:Decrypt, which the execution role is granted.

  • BKeep Lambda's default encryption at rest with the AWS managed key

    Incorrect

    Default encryption at rest needs no KMS permissions from users, so anyone who can view the function's configuration sees the plaintext value.

  • CUse a customer managed key for encryption at rest, with no other change

    Incorrect

    With a customer managed key at rest, users who have access to the key can still view the variables in plaintext, and the administrators have that access.

  • DMove the token from the variable into the function code as a constant

    Incorrect

    Hard-coded credentials can be read by anyone who can inspect the code, the opposite of what the rule requires.

Encryption at rest protects stored variables but shows them to permitted users; client-side encryption with the helpers keeps them ciphertext until the code decrypts them.

Question 4 · choose 1

An application writes request details to an Amazon CloudWatch Logs log group, and some log events contain customer email addresses. Compliance requires these addresses to be masked wherever the logs are read, including CloudWatch Logs Insights and subscription filters, and only a small security team may see them unmasked. The developer wants to avoid changing the application code. What should the developer do?

  1. ATurn on Amazon Macie and point its discovery jobs at the log group
  2. BAssociate a customer managed AWS KMS key with the log group
  3. CA data protection policy, with logs:Unmask only for the security team
  4. DAdd a metric filter that counts log events containing an email address
Show the answer and why
  • ATurn on Amazon Macie and point its discovery jobs at the log group

    Incorrect

    Macie discovers sensitive data in Amazon S3 general purpose buckets. It does not mask data in CloudWatch Logs.

  • BAssociate a customer managed AWS KMS key with the log group

    Incorrect

    A KMS key encrypts the log data at rest, but CloudWatch Logs decrypts it whenever it is requested, so readers still see the addresses.

  • CA data protection policy, with logs:Unmask only for the security team

    Correct

    A data protection policy masks matching sensitive data as it is ingested, at every egress point including Logs Insights and subscription filters. Only principals with logs:Unmask see the original.

  • DAdd a metric filter that counts log events containing an email address

    Incorrect

    A metric filter turns matching log data into a numeric metric. The email addresses stay visible in the log events.

Log group data protection policies mask sensitive data at ingestion; the logs:Unmask permission controls who may see it.

Question 5 · choose 2

A multi-tenant SaaS application keeps every tenant's data in one Amazon DynamoDB table, and each item's partition key value is the tenant ID. An AWS Lambda function serves requests with its execution role, which can read the whole table, and it filters items by tenant in code. The security team wants IAM itself to stop a request from reading another tenant's items, even if the code has a bug. Which TWO changes meet this requirement? (Choose TWO.)

  1. AKeep the current role, and add unit tests that check the tenant filter in the code
  2. BCreate a global secondary index for each tenant and query only that index
  3. CReplace each Query with a Scan that filters on the caller's tenant ID
  4. DA tenant-access role whose policy sets dynamodb:LeadingKeys to ${aws:PrincipalTag/TenantId}
  5. EPer request, assume that role with a TenantId session tag from the verified token
Show the answer and why
  • AKeep the current role, and add unit tests that check the tenant filter in the code

    Incorrect

    A test checks the code, but the role can still read every item. The requirement is for IAM to restrict which items a request can access.

  • BCreate a global secondary index for each tenant and query only that index

    Incorrect

    Indexes change how data is queried, not who may read it. A role that can read the table can still read every item.

  • CReplace each Query with a Scan that filters on the caller's tenant ID

    Incorrect

    A Scan reads every item before the filter is applied, and the role can still read all tenants' data.

  • DA tenant-access role whose policy sets dynamodb:LeadingKeys to ${aws:PrincipalTag/TenantId}

    Correct

    The dynamodb:LeadingKeys condition limits access to items whose partition key matches the given value, and aws:PrincipalTag reads the tenant from the session's tags.

  • EPer request, assume that role with a TenantId session tag from the verified token

    Correct

    Session tags passed with AssumeRole become principal tags of the session, so each request runs with credentials scoped to its own tenant.

Attribute-based access control: a session tag carries the tenant, and a dynamodb:LeadingKeys condition on aws:PrincipalTag enforces it per item.

Question 6 · choose 1

A new service needs database credentials at runtime. The security team requires that the credentials be stored encrypted and rotated automatically on a schedule, without the team writing a scheduler. Where should the developer store the credentials?

  1. AIn AWS Secrets Manager, with rotation turned on for the secret
  2. BIn a SecureString parameter in Parameter Store, in the standard tier
  3. CIn an encrypted environment variable of the service
  4. DIn a private Amazon S3 object encrypted with SSE-KMS
Show the answer and why
  • AIn AWS Secrets Manager, with rotation turned on for the secret

    Correct

    AWS recommends Secrets Manager for credentials, with purpose-built controls that include automatic rotation.

  • BIn a SecureString parameter in Parameter Store, in the standard tier

    Incorrect

    SecureString encrypts the value, but Parameter Store does not rotate the credentials for you.

  • CIn an encrypted environment variable of the service

    Incorrect

    Environment variables are set at deployment, so rotation would mean redeploying with new values by hand.

  • DIn a private Amazon S3 object encrypted with SSE-KMS

    Incorrect

    S3 stores the file encrypted but has no rotation for credentials inside it.

For secrets that need managed rotation, use Secrets Manager rather than configuration stores.

Question 7 · choose 1

A partner gives a team a temporary access token that is valid for 30 days. The token is stored as a SecureString parameter in Parameter Store. The team wants the parameter deleted automatically when the token expires so that it cannot be used by mistake. What should the developer do?

  1. APut the expiry date in the parameter's description
  2. BAdd a tag with the expiry date to the parameter
  3. CUse the advanced tier and attach an Expiration parameter policy
  4. DKeep it in the standard tier and add a label that marks it as temporary
Show the answer and why
  • APut the expiry date in the parameter's description

    Incorrect

    A description is informational; nothing acts on it when the date passes.

  • BAdd a tag with the expiry date to the parameter

    Incorrect

    Tags organize resources but do not delete a parameter by themselves.

  • CUse the advanced tier and attach an Expiration parameter policy

    Correct

    Parameter policies are available for advanced parameters, and an Expiration policy deletes the parameter at the date and time given.

  • DKeep it in the standard tier and add a label that marks it as temporary

    Incorrect

    The standard tier does not support parameter policies, so it cannot expire the parameter.

Advanced-tier parameter policies can expire parameters or send notifications before they expire.

Question 8 · choose 1

A DynamoDB table stores customer records, and the taxId attribute is highly sensitive. Operators who can read the table for support must not be able to see taxId values, while the application must still read and write them. Encryption at rest is already on. What should the developer add?

  1. ASwitch the table's encryption at rest to a customer managed key in AWS KMS
  2. BTurn on DynamoDB Streams with the NEW_AND_OLD_IMAGES view type
  3. CStore taxId in a second table that operators do not use
  4. DEncrypt taxId on the client with the AWS Database Encryption SDK
Show the answer and why
  • ASwitch the table's encryption at rest to a customer managed key in AWS KMS

    Incorrect

    Encryption at rest is transparent to anyone allowed to read the table, so operators would still see plaintext values.

  • BTurn on DynamoDB Streams with the NEW_AND_OLD_IMAGES view type

    Incorrect

    Streams capture changes; they do not hide attribute values from readers.

  • CStore taxId in a second table that operators do not use

    Incorrect

    Moving the value does not encrypt it, and anyone with read access to the second table could still see it.

  • DEncrypt taxId on the client with the AWS Database Encryption SDK

    Correct

    The SDK provides client-side, attribute-level encryption, so the stored value is ciphertext unless a caller can use the key.

Client-side, attribute-level encryption protects specific fields from people who can read the table but cannot use the key.

Question 9 · choose 1

A SecureString parameter in Parameter Store is encrypted with a customer managed KMS key. An application role has ssm:GetParameter on the parameter, and calls with WithDecryption set to true fail with an access error. Calls without decryption succeed. What should the developer add to the role's permissions?

  1. Akms:Decrypt on the customer managed key
  2. Bssm:PutParameter on the parameter
  3. Ckms:Encrypt on the customer managed key
  4. Dssm:GetParametersByPath on the parent path
Show the answer and why
  • Akms:Decrypt on the customer managed key

    Correct

    To decrypt a SecureString parameter value, the caller needs kms:Decrypt permission on the key that encrypted it.

  • Bssm:PutParameter on the parameter

    Incorrect

    PutParameter writes values; reading a value needs no write permission.

  • Ckms:Encrypt on the customer managed key

    Incorrect

    Encrypt is needed to write standard SecureString values, not to read them.

  • Dssm:GetParametersByPath on the parent path

    Incorrect

    The role can already read the parameter; the missing permission is on the KMS key.

Reading SecureString values needs both Parameter Store access and kms:Decrypt on the key.

Question 10 · choose 1

During a cleanup, a developer deletes an AWS Secrets Manager secret with the default settings. Two days later, a batch job fails because it still reads that secret. What should the developer do?

  1. ARestore the secret, which is possible until its deletion date
  2. BCreate a new secret with the same name and value from memory
  3. COpen an AWS Support case to recover the deleted secret
  4. DNothing can be done, because deletion is immediate and permanent
Show the answer and why
  • ARestore the secret, which is possible until its deletion date

    Correct

    Secrets Manager schedules deletion after a recovery window of at least seven days, and the secret can be restored until then.

  • BCreate a new secret with the same name and value from memory

    Incorrect

    The deleted secret still exists in its recovery window, and recreating values by hand risks errors.

  • COpen an AWS Support case to recover the deleted secret

    Incorrect

    The developer can restore the secret directly during the recovery window.

  • DNothing can be done, because deletion is immediate and permanent

    Incorrect

    Secrets Manager does not delete secrets immediately; it makes them inaccessible and schedules deletion.

Deleted secrets can be restored during the recovery window; an alarm on access attempts can catch secrets still in use.

Practise domain 2 →Practise all domains →