DVA-C02 Security Practice Question
A developer is deploying an application on EC2 that must access an S3 bucket. The developer wants to avoid hard-coding credentials. What is the MOST secure way to grant access?
⚠ Common exam trap
DVA-C02 often tests the misconception that environment variables or config files are acceptable for credentials, when the correct answer is always instance profiles with IAM roles for EC2 workloads.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an IAM role and attach it to the EC2 instance profile.
Attaching an IAM role to the EC2 instance profile lets the instance obtain temporary, automatically rotated credentials from the EC2 instance metadata service (IMDS), so no long-lived secrets exist on the instance or in code. This is the AWS-recommended best practice for EC2-to-S3 access and eliminates the risk of credential leakage. The SDKs and CLI automatically retrieve and refresh these credentials.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use an S3 bucket policy that allows access from the EC2 instance's public IP address.
Why it's wrong here
Using an S3 bucket policy that allows access from an EC2 instance's public IP address is an insecure and unscalable approach. Public IP addresses are not a reliable form of identity; they can change, especially with dynamic IP assignments or instance restarts, leading to broken access. This method only authorizes network origin, not the specific EC2 instance's identity, failing to provide proper authentication or granular authorization based on the instance itself.
- ✓
Create an IAM role and attach it to the EC2 instance profile.
Why this is correct
Creating an IAM role and attaching it to an EC2 instance profile is the AWS-recommended and most secure method for granting permissions. The instance profile acts as a container for the IAM role, allowing the EC2 instance to assume the role and obtain temporary, frequently rotated credentials from the EC2 metadata service. This eliminates the need to store long-term AWS credentials directly on the instance, significantly reducing the risk of credential compromise and adhering to the principle of least privilege.
- ✗
Set the AWS credentials as environment variables in the user data script.
Why it's wrong here
Setting AWS credentials as environment variables, even within a user data script, is a highly insecure practice. Any process running on the EC2 instance can potentially read these environment variables, meaning that if the instance is compromised, an attacker gains immediate access to the associated AWS resources. This method bypasses proper identity and access management controls and requires manual rotation and management of static credentials, increasing operational overhead and security risk.
- ✗
Store the AWS access key ID and secret access key in a configuration file on the instance.
Why it's wrong here
Storing static AWS access key IDs and secret access keys directly in a configuration file on an EC2 instance represents a severe security vulnerability. These long-term credentials never expire unless manually rotated, and if the file is accidentally exposed or the instance is compromised, an attacker gains persistent, full access to the AWS resources associated with those keys. This approach completely undermines the principle of least privilege and the use of temporary, identity-based credentials.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DVA-C02 question from scratch — 1,135 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.