Applications need database passwords, API keys and tokens. Hard-coding them in source code, Amazon Machine Images (AMIs), container images or environment files is a classic security failure: secrets end up in version control, logs and backups, anyone who can read the artifact can read the secret, and changing a secret means redeploying. The fix is to store secrets in a managed service, give each application's IAM role permission to read only its own secrets, and fetch them at runtime. AWS gives you two managed places to do this, and the exam asks you to pick between them.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.