Courseiva
Security →mediumMultiple Choice

DVA-C02 Security Practice Question

A company is using AWS CodeCommit for source control. Developers need to access the repository from their local machines. Which authentication method is recommended for secure access?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Generate and use SSH keys paired with an IAM user.

SSH keys provide secure access without storing credentials on the machine and can be paired with an IAM user for CodeCommit. Option A is wrong because IAM user password is for console access, not Git. Option B is wrong because while access keys can be used for Git credentials, they are long-term credentials and less secure than SSH keys. Option C is wrong because Cognito is for end-user authentication, not developer access to CodeCommit.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use IAM user name and password for Git credentials.

    Why it's wrong here

    While IAM users have a console password, this password is not used for authenticating Git operations with AWS CodeCommit. Git clients require specific credentials, such as HTTPS Git credentials generated within IAM for a user, or SSH keys, to interact with CodeCommit repositories. Directly using an IAM user's console password for Git authentication is not a supported mechanism and would fail.

  • ✗

    Use IAM access key and secret key for authentication.

    Why it's wrong here

    IAM access keys and secret keys are primarily designed for programmatic access to AWS APIs and services using the AWS CLI or SDKs. They are not directly used as credentials for authenticating Git operations with AWS CodeCommit repositories. Attempting to use these keys in place of Git-specific credentials (like HTTPS Git credentials or SSH keys) will result in authentication failures when pushing or pulling code.

  • ✗

    Use Amazon Cognito user pools for authentication.

    Why it's wrong here

    Amazon Cognito user pools are designed for managing user identities and authenticating users for web and mobile applications, providing sign-up and sign-in functionality. They are not an authentication mechanism for developers to access AWS CodeCommit repositories directly via Git. CodeCommit requires IAM-based authentication methods, such as SSH keys or HTTPS Git credentials, for developer access to source control.

  • ✓

    Generate and use SSH keys paired with an IAM user.

    Why this is correct

    Generating an SSH key pair and associating the public key with an IAM user is a secure and widely recommended method for authenticating Git operations with AWS CodeCommit. The private key resides on the developer's local machine, and CodeCommit uses the registered public key to verify the developer's identity during Git push/pull operations, ensuring secure access without exposing long-lived credentials. This method leverages standard Git SSH protocols.

About these practice questions

Courseiva writes every DVA-C02 question from scratch — 1,135 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.