All posts
11 min read

AWS Secrets Manager vs. Parameter Store: The Security Decision the SAA-C03 and DVA-C02 Both Test

AWS Secrets Manager and Systems Manager Parameter Store both store secrets — but only one rotates them automatically. Master the key differences and never lose a secure credential question on the SAA-C03 or DVA-C02 again.

Here is an exam scenario you will see on the SAA-C03:

A company runs a web application that connects to an Amazon RDS MySQL database. The security team requires that database credentials be rotated automatically every 90 days without any application downtime or code changes. Where should the credentials be stored?

Four answer choices: AWS Systems Manager Parameter Store. AWS Secrets Manager. AWS Key Management Service. Amazon S3 with server-side encryption.

The correct answer is AWS Secrets Manager — but only because of the word "automatically." Parameter Store can store the same credentials. KMS encrypts them but doesn't store them. S3 is not a secret-management service. The rotation requirement is what eliminates Parameter Store and makes Secrets Manager the only valid choice.

AWS Secrets Manager and Systems Manager Parameter Store look identical at first glance — both store key-value pairs, both integrate with AWS KMS, both are accessed via IAM, and both appear constantly on the SAA-C03 and DVA-C02. The exam exploits exactly this surface similarity to set traps. This guide gives you the mental model, the decision rules, and the exact signal words to answer every question correctly.


What AWS Secrets Manager Does

AWS Secrets Manager is a fully managed service for storing and rotating secrets — database credentials, API keys, OAuth tokens, SSH keys, and any credential that must remain confidential and that can be compromised if it stays static for too long.

How it works:

Secrets Manager stores each secret as a JSON key-value object (for example, {"username":"admin","password":"xkJ9!mQ3"}) or a plain string. Every secret is encrypted with AWS KMS — this is not optional. You must associate a KMS key with each secret, and Secrets Manager uses that key to encrypt the secret value at rest and decrypt it on each retrieval via GetSecretValue.

Automatic rotation:

The defining feature of Secrets Manager is its built-in automatic rotation. For supported databases — Amazon RDS (MySQL, PostgreSQL, Oracle, and SQL Server), Amazon Redshift, Amazon DocumentDB, Amazon Neptune, and MongoDB Atlas — Secrets Manager deploys a pre-built Lambda rotation function and schedules it to run at the interval you specify (daily, weekly, every 90 days, etc.). The rotation function creates a new credential version, updates it in the database, validates it, and only then marks the old version inactive. Your application code calls GetSecretValue on the same secret ARN — it gets the current active credential without any changes to your application.

For non-database secrets (third-party API keys, SSH keys, custom credentials), Secrets Manager provides a Lambda function template you extend with your own rotation logic.

Pricing:

  • $0.40 per secret per month
  • $0.05 per 10,000 API calls to Secrets Manager
  • Lambda rotation invocations are billed separately but cost under $0.01/month at typical rotation intervals

Cross-account and multi-region:

Secrets Manager supports resource-based policies attached directly to a secret. This means you can grant an IAM role in account B permission to call GetSecretValue on a secret in account A — without any intermediate infrastructure. For multi-region architectures, Secrets Manager can replicate a primary secret to secondary Regions automatically, keeping the replica in sync when the primary rotates.


What AWS Systems Manager Parameter Store Does

AWS Systems Manager Parameter Store is a hierarchical configuration store. It was built for application configuration — feature flags, database connection strings, service endpoints, environment names, license keys — and it handles secrets as a secondary capability through its SecureString type.

The three parameter types:

  • String — plaintext value, unencrypted at rest. Use for non-sensitive configuration like environment names, S3 bucket names, or region identifiers.
  • StringList — a comma-separated list of strings, also unencrypted. Use for lists of values your application needs to iterate.
  • SecureString — the value is encrypted with AWS KMS before storage and decrypted on retrieval. Use for passwords, API keys, and any value that must be protected at rest. On the SAA-C03 and DVA-C02, SecureString is always the correct choice when a question asks about storing sensitive values in Parameter Store.

Tier limits:

TierMax parametersMax value sizeCost
Standard10,0004 KBFree
Advanced100,0008 KB$0.05/parameter/month

Standard tier handles the vast majority of real-world use cases. If a scenario mentions hundreds of thousands of parameters or values larger than 4 KB, it is signaling the Advanced tier.

Hierarchical naming:

Parameter Store names are path-like: /app/prod/db/password, /app/prod/api/endpoint. You can retrieve all parameters under a path in one API call (GetParametersByPath), which is useful for loading an entire application's configuration at startup. Secrets Manager has no equivalent path structure — each secret has its own ARN.

What Parameter Store does not do:

Parameter Store has no built-in rotation. If you store a database password as a SecureString and need it to rotate, you write a Lambda function and schedule it with EventBridge yourself. The moment "automatic rotation" appears in an exam scenario, Parameter Store is eliminated.


The Decision Framework

AWS Secrets Manager vs Parameter Store decision tree for SAA-C03 — choosing based on rotation, sensitivity, cross-account access, and cost requirements

Work through these questions in order when a secret-storage scenario appears:

1. Does the scenario mention automatic rotation — on a schedule, without application changes, without custom code? → YES: Secrets Manager. No other answer is correct. Parameter Store cannot rotate automatically.

2. Is the value sensitive (a password, API key, private certificate)? → NO: Parameter Store String or StringList. Non-sensitive config belongs here — it's free, it's fast, and Secrets Manager is unnecessarily expensive for values like us-east-1 or feature-flag-enabled=true. → YES: Continue to question 3.

3. Does the scenario require cross-account access or replication to multiple AWS Regions? → YES: Secrets Manager. Only Secrets Manager supports a resource-based policy on the secret itself (cross-account) and built-in replica secrets (multi-region). → NO: Parameter Store SecureString (Standard tier, free). If the secret lives in one account, stays in one Region, and doesn't need automatic rotation, a KMS-encrypted SecureString is the correct cost-optimized answer.


The Feature Comparison

AWS Secrets Manager vs Parameter Store feature comparison matrix for SAA-C03 and DVA-C02 — automatic rotation, encryption, cost model, cross-account access, and multi-region replication

The comparison the exam tests most frequently:

Secrets ManagerParameter Store
Automatic rotation✓ Built-in (RDS, Redshift, DocumentDB, Neptune)✗ Custom Lambda only
EncryptionAlways (KMS mandatory)Optional (SecureString only)
Cost$0.40/secret/monthFree (Standard)
Cross-account✓ Resource-based policy✗ Not natively supported
Multi-region✓ Replica secrets✗ Manual re-creation
Max value size64 KB4 KB (Standard) / 8 KB (Advanced)

The Rotation Deep-Dive — Where Candidates Lose Points

The rotation mechanism is the SAA-C03's most commonly tested Secrets Manager behavior, and it is more nuanced than "it rotates the password." Here is how it actually works:

The dual-version lifecycle:

When Secrets Manager triggers a rotation:

  1. A new credential is created in the database (the new version has the AWSPENDING label).
  2. Secrets Manager tests that the new credential works.
  3. If the test passes, the new version gets the AWSCURRENT label and the old version gets AWSPREVIOUS.
  4. After a grace period, the AWSPREVIOUS version is deleted.

Your application always calls GetSecretValue for the AWSCURRENT version. Because the old credential stays valid (AWSPREVIOUS) during the rotation cycle, in-flight connections using the old password continue to work until they are recycled — this is what "no application downtime" means in exam scenarios. If you hardcoded the password in your application, rotation would break you. If you retrieve it from Secrets Manager on each connection, rotation is invisible.

The exam trap: Some scenarios describe a Lambda function that reads a database password from Secrets Manager once at cold start and caches it in memory. This architecture breaks on rotation — the Lambda holds the old password until the next cold start. The correct pattern is to retrieve the secret on each invocation, or to implement a short-lived local cache with an expiry aligned to your rotation interval. The DVA-C02 tests this caching trap specifically.


Exam Scenario Drills

Scenario 1 (SAA-C03): A company stores its Amazon RDS PostgreSQL credentials in AWS Secrets Manager. A newly hired security engineer asks why the application still works immediately after a rotation event. The engineer expected the old password to stop working at rotation time. What explains this behavior?

→ Secrets Manager keeps the AWSPREVIOUS version valid for the duration of the rotation window so in-flight connections are not disrupted. The old password is only invalidated after the grace period completes. This is the dual-version rotation design.

Scenario 2 (SAA-C03): A startup is building its first AWS application. A developer needs to store the application's database hostname, environment name (production), and a plaintext feature-flag value. Cost must be minimized. Which service and parameter type should be used?

→ Parameter Store Standard tier, String type. These are non-sensitive configuration values. SecureString (KMS encryption) is unnecessary and adds API call cost. Secrets Manager at $0.40/secret/month is overkill for three plaintext config values.

Scenario 3 (DVA-C02): A developer is building a Lambda function that retrieves a third-party payment API key from AWS Secrets Manager at Lambda cold start and stores it in a global variable. The security team has configured automatic rotation every 30 days. After a rotation event, some Lambda invocations fail with an authentication error. What is the root cause?

→ The Lambda function cached the AWSPREVIOUS password in its global variable and is using it after rotation completed. The fix is to either retrieve the secret on each invocation (adding a small latency cost) or implement a cache with a TTL shorter than the rotation interval, with logic to retry GetSecretValue when an authentication error occurs.

Scenario 4 (SAA-C03): A company's security policy requires all database credentials to be stored in a way that supports automatic rotation and cross-account access, so that a central security account can audit credential usage. Which service satisfies both requirements?

→ Secrets Manager. It is the only service that supports both automatic rotation and cross-account access via resource-based policy. Parameter Store cannot satisfy the cross-account requirement.

Scenario 5 (SAA-C03): A solutions architect must store 50,000 application configuration parameters including feature flags, service URLs, and environment names. Cost is the primary constraint. No parameters are sensitive. Which service and tier should be used?

→ Parameter Store Advanced tier (the Standard tier limit is 10,000 parameters). At $0.05/parameter/month for 50,000 parameters that is $2,500/month — but this is still the correct answer because Secrets Manager at $0.40/secret/month for 50,000 items would cost $20,000/month. The exam is testing whether you know the Standard tier limit and recognize the Advanced tier as the next option before reaching for Secrets Manager.


IAM Access Pattern

Both services use IAM for access control, but the actions are different — and the exam tests them:

Secrets Manager:

secretsmanager:GetSecretValue      # retrieve the secret
secretsmanager:DescribeSecret      # read metadata (not the value)
secretsmanager:RotateSecret        # trigger a manual rotation
kms:Decrypt                        # required if using a customer-managed KMS key

Parameter Store:

ssm:GetParameter                   # retrieve one parameter
ssm:GetParameters                  # retrieve up to 10 parameters by name
ssm:GetParametersByPath            # retrieve all parameters under a path prefix
kms:Decrypt                        # required for SecureString parameters

The key difference on the exam: if a scenario says "the IAM policy must allow the Lambda function to retrieve multiple configuration values under /app/prod/ in one API call," that is a GetParametersByPath pattern — Parameter Store, not Secrets Manager. Secrets Manager has no equivalent path-query operation.


The Signal Words — Quick Reference

If you see this in a scenarioAnswer
"automatically rotate" / "rotation schedule" / "rotate every N days"Secrets Manager
"no application code changes during rotation"Secrets Manager
"cross-account access to the secret"Secrets Manager
"replicate the secret to another Region"Secrets Manager
"store configuration values" / "feature flags" / "environment settings"Parameter Store
"minimize cost" + non-sensitive valuesParameter Store String (free)
"minimize cost" + sensitive values, single accountParameter Store SecureString (free)
"thousands of config parameters"Parameter Store (check Standard vs Advanced tier limit)
"retrieve all parameters under a path" / "GetParametersByPath"Parameter Store

Practice These Questions Before Your Exam

Security configuration questions — credential storage, rotation, encryption key management — appear in the SAA-C03's Design Secure Architectures domain (approximately 30% of the exam) and throughout the DVA-C02's security and configuration sections. If Secrets Manager vs. Parameter Store is a knowledge gap today, it will cost you points on exam day.

The free 10-question diagnostic shows you in 10 minutes exactly which security sub-domains need more work before exam day. If credential management is your gap, the SAA-C03 practice question set drills every rotation, cross-account, and encryption scenario across both services in the scenario-based format the real exam uses.

Working developers targeting the DVA-C02 will find the DVA-C02 practice set specifically tests the Lambda caching trap, the GetSecretValue vs GetParameter IAM action difference, and the dual-version rotation lifecycle in the exam's application-integration and security domains.

For the broader security-in-VPC picture, Security Groups vs. NACLs covers the stateful/stateless firewall pair that appears on the same domain, and VPC Endpoints — Gateway vs. Interface explains how to reach Secrets Manager and Parameter Store from a private VPC subnet without routing traffic over the public internet — a required piece of any secure application architecture.