mediumMultiple Choice
CCSP Practice Question: A cloud application uses IAM roles to grant…
A cloud application uses IAM roles to grant permissions to compute instances. What is the primary security advantage of this approach over hardcoding credentials?
⚠ Common exam trap
CCSP often tests the misconception that IAM roles improve performance or simplify networking, when the actual benefit is eliminating long-lived static credentials and enabling least-privilege, short-lived access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Elimination of hardcoded secrets
IAM roles issue short-lived, automatically rotated temporary credentials to compute instances via instance metadata (e.g., AWS IMDSv2, Azure Managed Identity, GCP service accounts), so no long-lived secret ever exists in code, config files, or repos. This removes the primary attack vector of credential theft via source code leaks, container image scraping, or log exposure. Because the credentials are ephemeral and scoped to the role's policy, blast radius from a compromised instance is also limited.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Simplified load balancing
Why it's wrong here
Load balancing distributes traffic across targets and is unrelated to credential storage. IAM roles supply short-lived credentials through instance metadata, removing hardcoded secrets. Load balancing configuration belongs to traffic distribution and health-check design, not to identity and access management.
- ✓
Elimination of hardcoded secrets
Why this is correct
IAM roles let compute instances obtain short-lived credentials automatically from the instance metadata service, so no long-lived secret is stored in code or configuration. This directly satisfies the stem's constraint: removing hardcoded credentials eliminates the primary leak vector, since rotating tokens expire and cannot be extracted from source repositories.
- ✗
Improved application performance
Why it's wrong here
Performance depends on compute, memory and I/O, not credential delivery. IAM roles eliminate stored static secrets by issuing temporary, automatically rotated credentials. Performance tuning belongs to instance sizing, autoscaling or query optimisation, not identity design.
- ✗
Reduced network latency
Why it's wrong here
Latency is a network transport characteristic, unaffected by how credentials are supplied to an instance. IAM roles remove long-lived secrets from instance metadata and rotate them automatically. Latency reduction belongs to content delivery networks, caching layers or region placement.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.