Full AWS Practitioner Certification Question

Rather than storing sensitive data, such as API keys or passwords, directly in a resource definition file, where should you securely store this information?