Courseiva

GCIH Securing Credentials and Data in Cloud Practice Question

An organization is migrating to AWS and needs to ensure that IAM users do not possess long-term credentials. Which approach provides the most secure mechanism for programmatic access?

⚠ Common exam trap

Candidates frequently select long-term access keys configured with multi-factor authentication, forgetting that programmatic access requires automated temporary credentials.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement IAM roles that grant temporary security credentials via STS.

Utilizing IAM roles with temporary security credentials is the best practice for cloud security. By assuming roles, you eliminate the risks associated with static access keys, which are frequently leaked or stolen. This approach aligns with the principle of least privilege, as temporary tokens expire automatically, reducing the window of opportunity for an attacker to exploit compromised credentials, thereby enhancing the overall security posture of the cloud environment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Generate unique access keys for every developer stored in an encrypted S3 bucket.

    Why it's wrong here

    Storing static access keys in S3, even when encrypted, creates a centralized point of failure. If an attacker gains permissions to decrypt the bucket or access the keys, the impact is significant. Static keys do not expire, making them a persistent target for adversaries seeking long-term persistence.

  • ✗

    Rotate IAM user access keys every 90 days via an automated script.

    Why it's wrong here

    Periodic rotation is a compensating control but does not address the fundamental flaw of long-term credentials. If a key is exfiltrated, rotation only limits the duration of the compromise. Roles with temporary credentials provide a much stronger security architecture by eliminating static secrets entirely from the ecosystem.

  • ✓

    Implement IAM roles that grant temporary security credentials via STS.

    Why this is correct

    IAM roles provide temporary security credentials that expire automatically, effectively mitigating the risk of credential theft. By leveraging AWS Security Token Service (STS), developers can assume roles only when needed. This approach eliminates the need for managing static keys, significantly reducing the attack surface for programmatic cloud access.

  • ✗

    Use an IAM group policy to enforce Multi-Factor Authentication on all API requests.

    Why it's wrong here

    Enforcing MFA on API calls is technically challenging and often requires complex workflows for automated systems. While MFA protects the console, it is not a direct substitute for using temporary credentials through IAM roles for programmatic access. It does not address the risk of compromised long-term access keys.

About these practice questions

This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.