Courseiva
Security →mediumMultiple Choice

CV0-004 Security Practice Question

A cloud operations team runs a containerized payroll application on Amazon EKS. Compliance requires that the application pod retrieve database credentials at runtime without embedding them in the container image, and that the credentials be rotated automatically every 30 days. Which approach BEST meets these requirements?

⚠ Common exam trap

The trap here is assuming that base64-encoded Kubernetes Secrets or environment variables provide secure secret handling, when they actually expose plaintext credentials and offer no rotation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Store the credentials in AWS Secrets Manager and use the AWS Secrets Manager and Config Provider for Secrets Store CSI Driver to inject them into the pod.

The requirement is runtime retrieval of database credentials plus automatic 30-day rotation without embedding secrets in the image. A secrets manager with native rotation integrated into the pod through the Secrets Store CSI Driver delivers both, mounting values as files and refreshing them on schedule. Base64 secrets, environment variables, and IAM role credentials each miss either the rotation or the runtime-injection aspect of the scenario.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create an IAM role for the service account and let the application call the database with IAM authentication credentials that never expire.

    Why it's wrong here

    IAM Roles for Service Accounts provides short-lived AWS API credentials, but it does not itself authenticate the application to a relational database unless that database supports IAM auth, and the claim that credentials never expire is incorrect. This approach also does not address rotation of the database password itself, so it fails the stated 30-day rotation requirement.

  • ✗

    Mount the credentials as a Kubernetes Secret created from a base64-encoded manifest stored in the Git repository.

    Why it's wrong here

    A Kubernetes Secret created from a base64-encoded manifest still places credential material in source control and in the cluster's etcd store. Base64 is encoding, not encryption, so anyone with repository or etcd read access can recover the plaintext. It also provides no automatic rotation mechanism, forcing manual regeneration and redeployment every 30 days, which conflicts with the compliance requirement.

  • ✓

    Store the credentials in AWS Secrets Manager and use the AWS Secrets Manager and Config Provider for Secrets Store CSI Driver to inject them into the pod.

    Why this is correct

    The Secrets Store CSI Driver with the AWS provider mounts Secrets Manager values directly into the pod as files, so nothing is baked into the image. Secrets Manager supports native rotation schedules, including every 30 days, and the auto-rotate feature refreshes the mounted files without a pod restart. This satisfies both the runtime retrieval and automatic rotation requirements.

  • ✗

    Inject the credentials as environment variables through the pod spec, referencing values held in an encrypted Amazon S3 bucket.

    Why it's wrong here

    Environment variables are visible to any process in the pod and appear in crash dumps and kubectl describe output, weakening confidentiality. Reading from S3 requires the pod to hold S3 permissions and network access, and S3 alone does not rotate credentials. The team would still need a custom job to refresh values, so automatic 30-day rotation is not delivered.

About these practice questions

Courseiva writes every CV0-004 question from scratch — 834 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.