CV0-004 Operations and Support Practice Question
A cloud administrator is responsible for a set of Linux virtual machines in AWS. The administrator needs to run a script on all of the instances at a scheduled time each night to rotate application logs. The script must run without the administrator logging in to each instance, and the administrator wants to avoid managing SSH keys for this task. Which AWS service should the administrator use?
⚠ Common exam trap
The trap here is assuming that any AWS service that observes or audits instances, such as CloudTrail or Config, can also execute operational tasks on them.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Systems Manager Run Command
AWS Systems Manager Run Command is designed to run commands and scripts on managed instances at scale without requiring SSH access. It uses the Systems Manager agent and IAM roles for authentication, and it can be scheduled through maintenance windows or EventBridge rules, which matches the nightly log rotation requirement without SSH key management.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Trusted Advisor
Why it's wrong here
Trusted Advisor provides recommendations based on best practices across cost, security, fault tolerance, performance, and service quotas. It is an advisory service and does not have the capability to run commands or scripts on EC2 instances. It cannot fulfill the requirement to rotate logs on a schedule.
- ✗
AWS CloudTrail
Why it's wrong here
CloudTrail records API activity in the AWS account for auditing and governance. It logs actions but does not execute them on instances. It cannot run a log rotation script, and it does not provide remote command execution, so it does not meet the scenario's requirement.
- ✓
AWS Systems Manager Run Command
Why this is correct
Run Command is part of AWS Systems Manager and allows the administrator to run scripts or commands on managed instances without SSH access. It uses the Systems Manager agent and IAM permissions, so no SSH keys are needed. It can be scheduled through a maintenance window or EventBridge, satisfying the nightly execution requirement.
- ✗
AWS Config
Why it's wrong here
AWS Config records resource configuration changes and evaluates compliance against rules. It does not execute scripts or commands on instances. While it can detect whether a configuration changed, it cannot perform the log rotation task described, so it is not the appropriate service for this operational need.
Go deeper
Related to this question
About these practice questions
One of 834 original CV0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.