CV0-004 Deployment Practice Question
A company is deploying a containerized application on Amazon EKS. The security team requires that the application pods use an IAM role to access AWS services without storing credentials in the container images or environment variables. Which approach should the team use?
⚠ Common exam trap
The trap here is assuming that node-level IAM roles or Kubernetes secrets are sufficient, but they either grant excessive permissions or still involve stored credentials.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a Kubernetes service account and associate it with an IAM role using IAM Roles for Service Accounts (IRSA).
IAM Roles for Service Accounts (IRSA) is the AWS-recommended method to grant AWS permissions to individual pods in an EKS cluster. By associating a Kubernetes service account with an IAM role, the pod can obtain temporary credentials via the cluster's OIDC provider. This approach adheres to least privilege and eliminates the need to store or manage long-term credentials in images or environment variables.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use the AWS SDK for Java with a custom credential provider that reads from the pod's environment variables.
Why it's wrong here
Reading credentials from environment variables still requires storing them somewhere, such as in the pod spec or a ConfigMap, which is insecure and does not eliminate stored credentials. The requirement explicitly states no credentials in environment variables. IRSA avoids this by using projected tokens and IAM roles.
- ✗
Attach an IAM role to the EC2 worker nodes and rely on the instance metadata service for pod credentials.
Why it's wrong here
Attaching an IAM role to worker nodes grants all pods on those nodes the same permissions, which violates the principle of least privilege. Pods could access AWS services with the node's role, potentially leading to privilege escalation. IRSA provides fine-grained, pod-level permissions, which is the recommended approach for EKS.
- ✓
Create a Kubernetes service account and associate it with an IAM role using IAM Roles for Service Accounts (IRSA).
Why this is correct
IAM Roles for Service Accounts (IRSA) allows Kubernetes pods to assume an IAM role via a service account. The EKS cluster's OIDC provider is used to federate the service account to IAM, and the pod receives temporary credentials through a projected service account token. This eliminates the need to store credentials in images or environment variables, meeting the security requirement.
- ✗
Store AWS credentials in a Kubernetes secret and mount it as a volume in the pod.
Why it's wrong here
Kubernetes secrets are base64-encoded and not encrypted by default. Storing long-term AWS credentials in a secret still requires managing and rotating them, and they could be exposed. This does not meet the requirement of avoiding stored credentials and is less secure than using IRSA, which provides temporary credentials automatically.
Go deeper
Related to this question
About these practice questions
This CV0-004 question is part of Courseiva's 834-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.