Pass the current credentials as AWS CLI command-line options for highest precedence without conflict

Answer Correct answer: C — pass the current credentials as AWS CLI command-line options, which take highest precedence and do not conflict with other configured credentials.

A developer is receiving AccessDenied errors when the developer invokes API calls to AWS services from a workstation. The developer previously configured environment variables and configuration files on the workstation to use multiple roles with other AWS accounts. A security engineer needs to help the developer configure authentication. The current credentials must be evaluated without conflicting with other credentials that were previously configured on the workstation. Where these credentials should be configured to meet this requirement?

  1. In the local AWS CLI configuration file
  2. As environment variables on the local workstation
  3. As variables in the AWS CLI command line options Correct Answer
  4. In the AWS shared configuration file

Community Votes

C
71%
D
29%

71% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The CLI credential precedence order is command-line options > environment variables > CLI config > shared config file. Supplying the current credentials as command-line options (C) wins over the older env-var/config credentials for that invocation and does not modify the persistent configuration, avoiding conflict. Environment variables (B) would also override but persist for the session and risk conflicting; the config/shared files (A/D) are lower precedence and would be overridden by the existing env vars. C is correct.

A developer's workstation has multiple roles configured via env vars and CLI config files, and new calls fail with AccessDenied. To evaluate the current credentials without conflicting with the previously configured ones, supply them as AWS CLI command-line options—these have the highest precedence in the credential chain and apply only to that command, so they override (without altering) the other stored credentials.

Editing the CLI config (A) or shared config file (D)—both are lower precedence than the existing environment variables, so the old credentials would still win, and they alter persistent config. Relying on environment variables (B)—they override config but persist for the session and can still conflict with other tooling. Command-line options (C) are highest precedence and scoped to the command.

Community Discussion (4 comments)

phmeeeee 👍 1 Selected: C
C - export AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY as variables
IPLogic 👍 3 Selected: C
To configure the current credentials without conflicting with other previously configured credentials on the workstation, the best option is: C. As variables in the AWS CLI command line options This approach ensures that the specific set of credentials needed for the current task can be provided directly in the CLI command itself, thus avoiding any potential conflicts with the environment variables or configuration files that might contain other credentials for different roles or accounts. Configuring credentials this way ensures that each command can be executed with its own specific set of credentials, without affecting the global or shared configurations on the workstation.
723993f 👍 1 Selected: C
Credential Precedence (Highest to Lowest): - Command Line Options - Environment Variables - CLI config file - Shared config file using Command Line Options would mean it will limited to until the session is active, next time when these options are not used, it will fall back to environment variables
rhsilva 👍 2 Selected: D
To avoid conflicts with previously configured credentials and ensure proper evaluation, the credentials should be configured in the AWS shared configuration file (option D). This file, typically located at ~/.aws/config on Linux and macOS or C:\Users\<username>\.aws\config on Windows, allows you to manage multiple profiles and roles without interfering with environment variables or local configuration files1

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The AWS CLI credential chain resolves in this precedence: command-line options, then environment variables, then the CLI config file, then the shared config file. Passing the current credentials as command-line options (C) gives them the highest precedence for that invocation and does not modify the workstation's stored configuration, so they are evaluated cleanly without conflicting with the other previously configured credentials.

Why the Other Options Are Wrong

A and D write to the CLI/shared config files, which sit below environment variables in precedence, so the existing env-var credentials would still win and the conflict remains. B uses environment variables, which override config but persist for the session and can still clash with other tooling. C is the scoped, highest-precedence choice.

Community Comment Notes

Community voted C (71), with D a 29 minority. Commenters cited the credential precedence chain (command-line options highest) and that options are limited to the command/session, avoiding conflict with previously configured credentials. C confirmed.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide