Courseiva
mediumMultiple Choice

CCSP Practice Question: A cloud application uses IAM roles to grant…

A cloud application uses IAM roles to grant permissions to compute instances. What is the primary security advantage of this approach over hardcoding credentials?

⚠ Common exam trap

CCSP often tests the misconception that IAM roles improve performance or simplify networking, when the actual benefit is eliminating long-lived static credentials and enabling least-privilege, short-lived access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Elimination of hardcoded secrets

IAM roles issue short-lived, automatically rotated temporary credentials to compute instances via instance metadata (e.g., AWS IMDSv2, Azure Managed Identity, GCP service accounts), so no long-lived secret ever exists in code, config files, or repos. This removes the primary attack vector of credential theft via source code leaks, container image scraping, or log exposure. Because the credentials are ephemeral and scoped to the role's policy, blast radius from a compromised instance is also limited.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Simplified load balancing

    Why it's wrong here

    Load balancing distributes traffic across targets and is unrelated to credential storage. IAM roles supply short-lived credentials through instance metadata, removing hardcoded secrets. Load balancing configuration belongs to traffic distribution and health-check design, not to identity and access management.

  • ✓

    Elimination of hardcoded secrets

    Why this is correct

    IAM roles let compute instances obtain short-lived credentials automatically from the instance metadata service, so no long-lived secret is stored in code or configuration. This directly satisfies the stem's constraint: removing hardcoded credentials eliminates the primary leak vector, since rotating tokens expire and cannot be extracted from source repositories.

  • ✗

    Improved application performance

    Why it's wrong here

    Performance depends on compute, memory and I/O, not credential delivery. IAM roles eliminate stored static secrets by issuing temporary, automatically rotated credentials. Performance tuning belongs to instance sizing, autoscaling or query optimisation, not identity design.

  • ✗

    Reduced network latency

    Why it's wrong here

    Latency is a network transport characteristic, unaffected by how credentials are supplied to an instance. IAM roles remove long-lived secrets from instance metadata and rotate them automatically. Latency reduction belongs to content delivery networks, caching layers or region placement.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.