An AWS scenario describes a value your application must read at runtime, and two of the options look reasonable. One is AWS Systems Manager Parameter Store. The other is AWS Secrets Manager. The deciding factor is rotation. If the question says the value must rotate on a schedule, the answer is Secrets Manager. If it is a configuration value, a feature flag, or a secret your team manages by hand, Parameter Store does the job at lower cost.
AWS draws the same line in its documentation. The Parameter Store overview page recommends Secrets Manager for database credentials, API keys, and tokens, because it provides purpose-built security controls including automatic rotation and cross-region replication (AWS Systems Manager Parameter Store overview).
When the question mentions rotation, the answer is decided
Secrets Manager lets you set up an automatic rotation schedule for a secret, and AWS describes the payoff in one line. Rotation lets you "replace long-term secrets with short-term ones, significantly reducing the risk of compromise" (What is AWS Secrets Manager?). Rotation comes in two forms. Managed rotation has the service configure and manage rotation without a Lambda function, and for other types of secrets the rotation runs in a Lambda function (Rotate AWS Secrets Manager secrets). The "Where should I store my application data?" table on the Parameter Store overview page lists credential rotation as "Automatic, with native database integrations" for Secrets Manager and "None" for Parameter Store.
Phrases in a question that point to Secrets Manager:
- "rotate on a schedule" or "automatically rotate"
- database credentials or API keys with a security or compliance requirement attached
- a statement that long-term credentials must be replaced over time
If the question says nothing about rotation, rotation is not part of the decision.
The other requirements, in the order you check them
Cross-account sharing. The same comparison table lists cross-account access among the use cases that point to Secrets Manager. Parameter Store shares across accounts only at the advanced tier, through an AWS Resource Access Manager (AWS RAM) resource share. "To share a parameter, it must be in the advanced parameter tier," and a shared SecureString must be encrypted with a customer managed KMS key, shared separately (Working with shared parameters in Parameter Store). If the value is a secret, a question that says it must be readable from another AWS account points to Secrets Manager. If it is a configuration value, an advanced-tier parameter shared through an AWS RAM resource share meets the same requirement.
Cost. Standard parameters cost nothing. "Standard parameters are available at no additional charge," and API interactions at standard throughput carry no charge. Advanced parameters cost $0.05 per parameter per month, prorated hourly, and their API interactions cost $0.05 per 10,000 at standard and higher throughput. Opting standard parameters into higher throughput bills their interactions at $0.05 per 10,000 (AWS Systems Manager pricing). Secrets Manager bills per secret and per API call. The pricing page's examples use $0.40 per secret per month and $0.05 per 10,000 API calls, and a replica secret bills as a distinct secret (AWS Secrets Manager pricing). A question that says you have thousands of values and asks you to minimize cost points to standard Parameter Store.
Value size. Parameter Store limits each standard value to 4 KB and each advanced value to 8 KB (Choosing parameter tiers in Parameter Store). If the value in the question is larger than 8 KB, Parameter Store cannot hold it. Check the quotas section of the AWS Secrets Manager User Guide for the current per-secret limit.
Requirements that do not discriminate between the two. Both services encrypt values with AWS KMS, though Parameter Store encryption is optional and applies only to SecureString values, while Secrets Manager encrypts with an AWS managed or customer managed key. Both keep a version history. Parameter Store retains the 100 most recent versions of each parameter, and Secrets Manager versions with staging labels. Both can be referenced from CloudFormation, Lambda functions, ECS and Fargate tasks, and CodeBuild. A question that mentions encryption, versioning, or referencing from other services is telling you something the answer options already share, so look for the requirement the question adds on top.
The full comparison and the verdict
| Attribute | Parameter Store | Secrets Manager |
|---|---|---|
| What it is built for | Static configuration. AMI IDs, environment variables, endpoint URLs, resource identifiers, tuning parameters | Credentials and other secrets, including values that need automatic rotation, cross-account access, or fine-grained audit logging |
| Value size | 4 KB (standard), 8 KB (advanced) | 64 KB (as of September 2026) |
| Rotation | None built in | Automatic. Managed rotation and Lambda-based rotation, with native database integrations |
| Cross-account sharing | Advanced tier only, via an AWS RAM resource share | Resource policy on the secret |
| Encryption | Optional, with SecureString and KMS | Always, with an AWS managed or customer managed key |
| Versioning | Keeps the 100 most recent versions | Versioning with staging labels |
| Cost (as of September 2026) | Standard free, storage and standard-throughput API interactions included. Advanced is $0.05 per parameter per month. Higher-throughput interactions $0.05 per 10,000 | $0.40 per secret per month plus $0.05 per 10,000 API calls (pricing-page examples). Replica secrets bill separately |
| Verdict | Pick it when the value is configuration or a manually managed secret and the question cares about cost | Pick it when the question requires scheduled rotation or cross-account sharing |
Cases that change the answer
A value called a "secret" in the question does not have to go to Secrets Manager. A SecureString parameter is an encrypted value in Parameter Store. If the question says nothing about rotation or cross-account sharing, the standard SecureString is the cheaper fit.
An encryption requirement does not break the tie, because both services encrypt with KMS. If the question stresses encryption and the answer options are the two stores, look for the requirement the question adds on top of encryption.
When rotation and cost both appear, rotation wins. The requirement the question states is scheduled rotation, and the exam asks which service provides it.
Watch the distractor services. AWS's Secrets Manager documentation steers other value types to other services: IAM for AWS credentials, KMS for encryption keys, EC2 Instance Connect for SSH keys, and Certificate Manager for private keys and certificates. When one of those appears in the answer options, the question is testing whether the value fits that service's job.
A worked case where the requirements point at different services
A small web app reads twelve configuration values, such as endpoint URLs, feature flags, and region names, plus one RDS credential. The security team requires the database credential to rotate on a 30-day schedule, and the team wants to keep the monthly bill as low as possible.
Put the RDS credential in Secrets Manager and enable automatic rotation. The rotation requirement is the constraint the other option cannot satisfy, because Parameter Store has no built-in rotation. Keep the twelve configuration values in standard Parameter Store, where storage and standard-throughput API interactions carry no charge. The bill is one secret at $0.40 per month plus whatever API calls the app makes.
The two tempting wrong calls are the flip side of each other. Storing the credential in a SecureString because it is free skips the rotation requirement the question stated, so the free option is the wrong one. Storing all thirteen values in Secrets Manager to keep them together pays the $0.40 per-secret rate for twelve values that never rotate, $4.80 per month. The question's two constraints, rotation and cost, point at different services, and the correct design uses both.
Where this decision sits on the two exams
Both exams report a scaled score of 100-1,000 with a minimum passing score of 720, and each includes 50 scored questions plus 15 unscored questions that AWS evaluates for future use. Per the current AWS exam guides:
- DVA-C02 (exam guide): 130 minutes. Development with AWS Services 32% of scored content, Security 26%, Deployment 24%, Troubleshooting and Optimization 18%.
- SAA-C03 (exam guide): Design Secure Architectures 30%, Design Resilient Architectures 26%, Design High-Performing Architectures 24%, Design Cost-Optimized Architectures 20%.
After a practice test, look at where it flags gaps: rotation, cross-account sharing, cost, or value size. Retest that area with the scenarios from this page before your next practice test.
The free assessment that tests this decision
Take the free CramHQ assessment for the exam you are sitting. For DVA-C02 it is the free AWS DVA-C02 assessment, and for SAA-C03 it is the free AWS SAA-C03 assessment. Both require no credit card and give you a Readiness Report, your top gaps, and a targeted repair preview before the full Pass Plan. The courses are $34.99 for 12 months of access. Find the gap that led to the wrong answer, do the repair, then retest similar scenarios.
