QuestionQ40

Identity and Access Management

A company uses Amazon Elastic Container Service (Amazon ECS) to deploy an application that handles sensitive data. In a recent security audit, the company found a security issue: Amazon RDS credentials were stored with the application code in the company's source code repository.

A security engineer must design a solution that ensures database credentials are stored securely and rotated on a periodic basis. Only the application should be able to access the credentials. The engineer must also prevent database administrators from sharing database credentials in plaintext with other teammates. The solution must minimize administrative overhead.

Which solution satisfies these requirements?

Explanation

AWS Secrets Manager securely stores database credentials and supports automatic rotation, removing the need to distribute or manually rotate plaintext passwords. An IAM role assigned to an ECS task supplies task-specific permissions, allowing the application task to retrieve only its authorized secret while withholding that access from other identities.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!