AWS Certified CloudOps Engineer - Associate
Secrets Management
Where credentials belong on AWS and why: Parameter Store tiers and SecureString, Secrets Manager rotation and staging labels, cross-account access, and the failures each design produces.
Intermediate 26 minutes 6 Learning Objectives
- Choose between Secrets Manager, Parameter Store, and AppConfig for a stated requirement
- Apply Parameter Store's standard and advanced tier limits to a design decision
- Trace a secret through the 4 rotation steps and the AWSCURRENT, AWSPENDING, and AWSPREVIOUS staging labels
- Compare single user and alternating users rotation, and identify when managed rotation applies
- Configure cross-account and cross-Region access to a secret, including the KMS key requirement
- Diagnose common secret retrieval, rotation, and deletion failures
