AWS Certified Security - Specialty

AWS Certified Security - Specialty

Get started today

Ultimate access to all questions.


A security engineer is tasked with auditing an AWS CloudFormation template and identifies a parameter that inadvertently exposes an application's API key in plaintext by default. This parameter is used in multiple locations within the template. The engineer must address this vulnerability by replacing the parameter in a way that ensures the API key can still be securely referenced throughout the template. Which of the following solutions offers the highest level of security for managing this sensitive information?