CLF-C02 Security and Compliance Practice Question
An application running on an Amazon EC2 instance needs to access an Amazon S3 bucket. The security team requires that no long-term access keys be stored on the instance. Which IAM feature should be used to grant the EC2 instance permission to access S3?
⚠ Common exam trap
Watch out — candidates often confuse IAM roles with IAM users or groups, thinking that any IAM entity can be attached to an EC2 instance, but only IAM roles support the temporary credential workflow required for secure, keyless access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Attach an IAM role to the EC2 instance
An IAM role can be attached to an EC2 instance, allowing the instance to obtain temporary security credentials from AWS STS via the instance metadata service. This eliminates the need to store long-term access keys on the instance, satisfying the security team's requirement. The EC2 instance automatically rotates these temporary credentials before they expire, providing secure, programmatic access to the S3 bucket.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create an IAM user and embed the access key in the application code
Why it's wrong here
Creating an IAM user for an EC2 application and embedding the access key ID and secret access key directly in source code is insecure because these are long-term static credentials. If the code is committed to a repository, pushed to a CI/CD system, or packaged into an AMI, the keys can be exfiltrated and there is no automatic rotation. Unlike a role attached to the instance, you must manually rotate and manage those keys, and they grant broad permissions for as long as they remain valid.
- ✗
Store the access key in an EC2 environment variable
Why it's wrong here
Storing an IAM user's access key in an environment variable on the EC2 instance is still relying on a long-lived credential rather than temporary credentials. Any user or process on the instance, including a compromised dependency or an attacker with OS-level access, can read process environment variables via /proc/<pid>/environ, so the key is effectively available to anything running on the host. In contrast, an instance profile supplies short-lived, automatically rotated credentials from the metadata service.
- ✓
Attach an IAM role to the EC2 instance
Why this is correct
An IAM role attached to an EC2 instance (via an instance profile) provides temporary, automatically rotating credentials. The EC2 metadata service delivers these credentials to the application, eliminating the need to store any long-term access keys.
- ✗
Use an IAM group to assign the permissions to the EC2 instance
Why it's wrong here
IAM groups are purely a container for IAM users; group policies are evaluated only when the IAM user making the request is a member of the group. An EC2 instance is not an IAM principal and cannot be added to a group, so assigning the group to the instance is not a valid operation. To grant permissions to an EC2 instance, you attach an IAM role to the instance profile, and the instance acquires the role's temporary credentials through the instance metadata service.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 993 original CLF-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.