Courseiva
Security →hardMultiple Choice

DVA-C02 Security Practice Question

A developer is deploying an application on EC2 that must access an S3 bucket. The developer wants to avoid hard-coding credentials. What is the MOST secure way to grant access?

⚠ Common exam trap

DVA-C02 often tests the misconception that environment variables or config files are acceptable for credentials, when the correct answer is always instance profiles with IAM roles for EC2 workloads.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an IAM role and attach it to the EC2 instance profile.

Attaching an IAM role to the EC2 instance profile lets the instance obtain temporary, automatically rotated credentials from the EC2 instance metadata service (IMDS), so no long-lived secrets exist on the instance or in code. This is the AWS-recommended best practice for EC2-to-S3 access and eliminates the risk of credential leakage. The SDKs and CLI automatically retrieve and refresh these credentials.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use an S3 bucket policy that allows access from the EC2 instance's public IP address.

    Why it's wrong here

    Using an S3 bucket policy that allows access from an EC2 instance's public IP address is an insecure and unscalable approach. Public IP addresses are not a reliable form of identity; they can change, especially with dynamic IP assignments or instance restarts, leading to broken access. This method only authorizes network origin, not the specific EC2 instance's identity, failing to provide proper authentication or granular authorization based on the instance itself.

  • ✓

    Create an IAM role and attach it to the EC2 instance profile.

    Why this is correct

    Creating an IAM role and attaching it to an EC2 instance profile is the AWS-recommended and most secure method for granting permissions. The instance profile acts as a container for the IAM role, allowing the EC2 instance to assume the role and obtain temporary, frequently rotated credentials from the EC2 metadata service. This eliminates the need to store long-term AWS credentials directly on the instance, significantly reducing the risk of credential compromise and adhering to the principle of least privilege.

  • ✗

    Set the AWS credentials as environment variables in the user data script.

    Why it's wrong here

    Setting AWS credentials as environment variables, even within a user data script, is a highly insecure practice. Any process running on the EC2 instance can potentially read these environment variables, meaning that if the instance is compromised, an attacker gains immediate access to the associated AWS resources. This method bypasses proper identity and access management controls and requires manual rotation and management of static credentials, increasing operational overhead and security risk.

  • ✗

    Store the AWS access key ID and secret access key in a configuration file on the instance.

    Why it's wrong here

    Storing static AWS access key IDs and secret access keys directly in a configuration file on an EC2 instance represents a severe security vulnerability. These long-term credentials never expire unless manually rotated, and if the file is accidentally exposed or the instance is compromised, an attacker gains persistent, full access to the AWS resources associated with those keys. This approach completely undermines the principle of least privilege and the use of temporary, identity-based credentials.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every DVA-C02 question from scratch — 1,135 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.