DVA-C02 Security Practice Question
A developer needs to allow an EC2 instance to access an S3 bucket without storing credentials on the instance. Which approach is the most secure?
⚠ Common exam trap
DVA-C02 often tests the misconception that storing credentials in Parameter Store or Secrets Manager is equivalent to using an IAM role — both still involve static secrets, whereas roles provide short-lived, auto-rotated credentials.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use an IAM role for EC2 with a policy granting S3 access.
An IAM role attached to an EC2 instance delivers temporary, automatically rotated credentials via the Instance Metadata Service (IMDS), so no long-lived secrets ever touch the instance filesystem. The role's trust policy allows ec2.amazonaws.com to assume it, and the attached permissions policy scopes exactly which S3 actions and resources are allowed. This is AWS's recommended pattern for granting AWS service access to compute resources.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create an IAM user with access keys and store them on the instance.
Why it's wrong here
Storing IAM user access keys on the EC2 instance is insecure because the keys are persistent and could be compromised if the instance is breached. The recommended approach is to use an IAM role for EC2, which provides temporary credentials automatically.
- ✗
Use S3 bucket policy to allow the EC2 instance's public IP.
Why it's wrong here
An S3 bucket policy keyed to a public IP grants anonymous access to anyone reaching that address, and EC2 public IPs change on stop/start unless an Elastic IP is attached. It is tempting because resource policies do govern S3 access, but they cannot authenticate an instance identity; an IAM role attached via an instance profile supplies temporary credentials instead.
- ✗
Store the access keys in Systems Manager Parameter Store and retrieve at runtime.
Why it's wrong here
Storing access keys in Parameter Store still requires the instance to authenticate to retrieve them, which reintroduces the credential-management problem the stem explicitly prohibits. The correct approach uses an IAM instance profile to grant temporary credentials via the EC2 metadata service, eliminating any stored secret. This option is tempting because Parameter Store securely encrypts static secrets, making it ideal for database passwords or API tokens in applications that already have an identity—but it cannot solve the bootstrap authentication loop for an EC2 instance itself.
- ✓
Use an IAM role for EC2 with a policy granting S3 access.
Why this is correct
An IAM role attached to the instance delivers temporary credentials through the instance metadata service, rotated automatically by AWS. No long-term access keys are stored on disk or in code, eliminating the credential-exposure risk the stem prohibits.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.