DVA-C02 Security Practice Question
A developer is deploying an application on Amazon ECS with Fargate. The application needs to access an S3 bucket that contains sensitive data. The developer wants to avoid storing AWS credentials in the container image. What is the MOST secure way to grant the application access to the S3 bucket?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an IAM task role with a policy that allows S3 access and specify it in the task definition.
An IAM task role for ECS tasks allows the container to assume the role without storing credentials. Option B is wrong because environment variables are not secure. Option C is wrong because mounting credentials in a volume is insecure. Option D is wrong because IAM instance profiles are for EC2 instances, not Fargate tasks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create an IAM task role with a policy that allows S3 access and specify it in the task definition.
Why this is correct
An ECS task IAM role, specified in the task definition, causes the ECS agent to inject temporary, automatically-rotated credentials into the container via the task metadata endpoint, so the application's SDK picks up scoped S3 permissions without any long-lived secret ever being stored or configured.
- ✗
Set the AWS credentials as environment variables in the task definition.
Why it's wrong here
Hardcoding static AWS access keys as environment variables in the task definition creates a long-lived credential that is visible in the ECS console, task definition JSON, and CloudTrail, and does not rotate automatically, making it the least secure and explicitly what the developer wants to avoid.
- ✗
Store the credentials in an EFS volume and mount it to the container.
Why it's wrong here
Persisting credentials on an EFS volume introduces a shared, persistent secret file that any task or principal with mount access to that file system could read, and it still requires manual rotation and secret management rather than leveraging AWS's native temporary credential vending.
- ✗
Use an IAM instance profile attached to the underlying EC2 instance.
Why it's wrong here
Fargate is a serverless compute engine for ECS that abstracts away the underlying EC2 host entirely, so there is no customer-managed EC2 instance to attach an instance profile to; this option describes an approach valid only for the EC2 launch type, not Fargate.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This DVA-C02 question is part of Courseiva's 1,135-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.