StudyToCert

All certifications / Cloud Practitioner / Lessons

AWS Certified Cloud Practitioner CLF-C02 · Domain 2: Security and Compliance

Storing credentials safely: AWS Secrets Manager and AWS Systems Manager Parameter Store

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

Applications need secrets: database passwords, API keys for third-party services, tokens and certificates. The worst place to keep them is in source code or in plain text configuration files on a server, where they get copied into code repositories, backups, container images and logs, and are hard to change once leaked. AWS offers two services for storing such values centrally and retrieving them at runtime with access controlled by AWS Identity and Access Management (IAM): AWS Secrets Manager and AWS Systems Manager Parameter Store.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study Cloud Practitioner for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the Cloud Practitioner study plan