Courseiva
Deployment →mediumMultiple Choice

CV0-004 Deployment Practice Question

A cloud administrator is deploying a new Amazon EC2 instance that must run a custom application. The application requires a specific IAM role to access an S3 bucket. The administrator wants to avoid embedding AWS credentials in the instance. What should the administrator do?

⚠ Common exam trap

The trap here is believing that storing credentials in Parameter Store or environment variables is equally secure, when they still require an IAM role or introduce static credentials.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an IAM role with the necessary S3 permissions and attach it to the EC2 instance using an instance profile.

The most secure and recommended way to grant an EC2 instance access to AWS services like S3 is to create an IAM role with the required permissions and attach it to the instance via an instance profile. The instance can then obtain temporary credentials from the instance metadata service, eliminating the need for hardcoded credentials and enabling automatic rotation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure the application to use the AWS SDK's default credential provider chain with environment variables set on the instance.

    Why it's wrong here

    Environment variables containing credentials are still long-term and can be exposed. While the default credential provider chain can use instance metadata, setting environment variables overrides that and introduces static credentials. The secure approach is to rely on the instance metadata credentials provided by an attached IAM role, not environment variables.

  • ✗

    Generate an access key and secret key for an IAM user, then store them in a configuration file on the instance.

    Why it's wrong here

    Storing long-term access keys on an EC2 instance is insecure because the keys can be accidentally exposed or compromised. AWS best practices strongly discourage embedding credentials in code or configuration files. Instead, temporary credentials from an IAM role should be used. This approach also requires manual rotation and increases management overhead.

  • ✗

    Use AWS Systems Manager Parameter Store to store the credentials and retrieve them at runtime.

    Why it's wrong here

    Parameter Store can securely store credentials, but the instance still needs permission to access Parameter Store. That permission would require an IAM role, which is the same as using an instance profile. Additionally, retrieving credentials from Parameter Store introduces complexity and potential latency. The direct and secure method is to attach an IAM role to the instance.

  • ✓

    Create an IAM role with the necessary S3 permissions and attach it to the EC2 instance using an instance profile.

    Why this is correct

    AWS recommends using IAM roles for EC2 instances to grant permissions without embedding long-term credentials. An instance profile is a container for an IAM role that can be attached to an EC2 instance at launch or later. The instance then retrieves temporary credentials from the instance metadata service, which are automatically rotated. This method is secure and aligns with best practices.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every CV0-004 question from scratch — 834 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.