Courseiva
Security →easyMultiple Choice

DVA-C02 Security Practice Question

A developer is creating an IAM policy to allow an EC2 instance to access an S3 bucket. Which AWS service should the developer use to securely provide credentials to the EC2 instance?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an IAM role and attach it to the EC2 instance profile.

IAM roles are designed to be assumed by AWS services like EC2. Instance profiles deliver temporary credentials to the EC2 instance automatically, avoiding hard-coded keys. Option A is incorrect because Cognito identity pools are intended for user identity in mobile/web apps, not for EC2 instances. Option B is incorrect because storing IAM user access keys on the instance is insecure and not recommended. Option D is incorrect because AWS Secrets Manager is for managing secrets such as database credentials, not for providing credentials to EC2 instances. Option C is the correct approach: create an IAM role with the necessary S3 permissions and attach it to the EC2 instance profile.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use Amazon Cognito identity pools to generate temporary credentials for the instance.

    Why it's wrong here

    Amazon Cognito identity pools are specifically designed to provide temporary, limited-privilege AWS credentials to authenticated end-users of mobile and web applications, enabling them to access AWS services directly. They are not intended or architected for authenticating AWS infrastructure components like EC2 instances, which require a machine identity mechanism. Using Cognito for EC2 instances would be an inappropriate application of the service's core purpose.

  • ✗

    Create an IAM user with access keys and store them on the instance.

    Why it's wrong here

    Creating an IAM user with static access keys and storing them directly on an EC2 instance is a severe security anti-pattern and violates best practices. These long-term credentials never expire unless manually rotated, making them highly vulnerable to compromise if the instance is breached or the keys are exfiltrated. This method lacks automatic rotation, secure distribution, and proper lifecycle management, posing a significant security risk.

  • ✓

    Create an IAM role and attach it to the EC2 instance profile.

    Why this is correct

    Creating an IAM role and attaching it to an EC2 instance profile is the secure and recommended best practice for granting AWS permissions to an EC2 instance. The instance profile acts as a container for the IAM role, allowing the instance to assume the role and obtain temporary, automatically rotated credentials. These credentials are securely provided through the EC2 instance metadata service, eliminating the need to store static access keys on the instance itself.

  • ✗

    Store the AWS access key in AWS Secrets Manager and retrieve it at runtime.

    Why it's wrong here

    Storing AWS access keys in Secrets Manager fails for an EC2 instance's own identity because the instance would still require credentials to access Secrets Manager itself, creating a circular dependency. The secure, native mechanism for an EC2 instance to obtain its own AWS credentials is via an IAM role attached to its instance profile, which provides temporary, automatically rotated credentials through the instance metadata service. Secrets Manager is appropriate for securely storing and retrieving application-specific secrets, such as database passwords or API keys for third-party services, where the instance already possesses its own identity.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.