Pass the current credentials as AWS CLI command-line options for highest precedence without conflict
A developer is receiving AccessDenied errors when the developer invokes API calls to AWS services from a workstation. The developer previously configured environment variables and configuration files on the workstation to use multiple roles with other AWS accounts. A security engineer needs to help the developer configure authentication. The current credentials must be evaluated without conflicting with other credentials that were previously configured on the workstation. Where these credentials should be configured to meet this requirement?
Community Votes
71% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The CLI credential precedence order is command-line options > environment variables > CLI config > shared config file. Supplying the current credentials as command-line options (C) wins over the older env-var/config credentials for that invocation and does not modify the persistent configuration, avoiding conflict. Environment variables (B) would also override but persist for the session and risk conflicting; the config/shared files (A/D) are lower precedence and would be overridden by the existing env vars. C is correct.
A developer's workstation has multiple roles configured via env vars and CLI config files, and new calls fail with AccessDenied. To evaluate the current credentials without conflicting with the previously configured ones, supply them as AWS CLI command-line options—these have the highest precedence in the credential chain and apply only to that command, so they override (without altering) the other stored credentials.
Editing the CLI config (A) or shared config file (D)—both are lower precedence than the existing environment variables, so the old credentials would still win, and they alter persistent config. Relying on environment variables (B)—they override config but persist for the session and can still conflict with other tooling. Command-line options (C) are highest precedence and scoped to the command.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.