Courseiva
Security →mediumMultiple Choice

CV0-004 Security Practice Question

A cloud administrator manages a fleet of Amazon EC2 instances hosting a stateless web tier. The security team requires that any administrative SSH access is logged to a tamper-evident, centralized location, and that the private keys never leave a hardware device. Which approach should the administrator implement?

⚠ Common exam trap

The trap here is assuming that storing SSH keys in a managed secret store or rotating them satisfies a requirement that private keys never leave a hardware device.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use AWS Systems Manager Session Manager with an EC2 instance profile and log sessions to Amazon CloudWatch Logs and S3.

Session Manager uses the Systems Manager agent and IAM instance profiles to broker shell access, so no inbound SSH port or private key distribution is required. Session logging to CloudWatch Logs and S3 with retention controls provides the tamper-evident, centralized audit trail. Together these meet both the key custody and logging requirements without exposing credentials.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Store SSH private keys in AWS Secrets Manager and retrieve them at instance boot via user data.

    Why it's wrong here

    Secrets Manager can store keys, but retrieving them via EC2 user data writes the private key into instance metadata and logs, defeating the requirement that keys never leave a hardware device. It also does not produce the tamper-evident, centralized session logging the security team demanded, because it only controls key distribution.

  • ✓

    Use AWS Systems Manager Session Manager with an EC2 instance profile and log sessions to Amazon CloudWatch Logs and S3.

    Why this is correct

    Session Manager provides shell access through the Systems Manager agent without opening inbound SSH ports or distributing private keys. Sessions can be recorded and streamed to CloudWatch Logs and S3 with object lock for tamper evidence, satisfying both the hardware-key and centralized-logging requirements.

  • ✗

    Deploy a bastion host with SSH certificate authority and forward all session logs to a syslog server.

    Why it's wrong here

    A bastion host with an SSH certificate authority reduces key sprawl, but the private keys still reside on client devices and the syslog server must be hardened separately for tamper evidence. It adds management overhead and does not inherently satisfy the requirement that keys never leave a hardware device.

  • ✗

    Configure EC2 key pairs and rotate them every 30 days using AWS Lambda and EventBridge.

    Why it's wrong here

    Rotating EC2 key pairs still requires storing private key material on administrator workstations and does not natively provide tamper-evident session logging. It also does not prevent keys from leaving hardware devices, and rotation alone does not record interactive sessions for audit, so it fails both stated requirements.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This CV0-004 question is part of Courseiva's 834-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.