QuestionQ30

Security and Compliance

A large enterprise is deploying a web application on AWS. The application runs on Amazon EC2 instances behind an Application Load Balancer. The instances run in an Auto Scaling group spanning multiple Availability Zones. The application stores data in an Amazon RDS Oracle DB instance and Amazon DynamoDB. Separate environments exist for development, testing, and production.

What is the MOST secure and flexible method to obtain password credentials during deployment?

Explanation

An EC2 IAM role supplies temporary AWS credentials to the application without distributing or managing static access keys, including across Auto Scaling instances. AWS Secrets Manager securely stores database credentials, provides IAM-controlled retrieval, and supports credential rotation, making it suitable for RDS database passwords and separate environments.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!