DVA-C02 Security Practice Question
A developer needs to allow an EC2 instance to read items from a DynamoDB table. Which is the best practice for granting permissions?
⚠ Common exam trap
DVA-C02 often tests the misconception that SCPs or bucket policies can grant permissions to an EC2 instance — candidates confuse organization-level guardrails (SCPs) with identity-based permissions (IAM roles), or think access keys are acceptable for convenience.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Attach an IAM role with the required permissions to the EC2 instance
Attaching an IAM role to the EC2 instance is the AWS best practice because it provides temporary, automatically rotated credentials via the instance metadata service (IMDS), eliminating the need to embed long-lived access keys. The role's policy grants only the required DynamoDB read permissions, following least privilege. This is the standard, secure, and auditable approach for EC2-to-AWS-service authentication.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Store IAM user access keys on the instance
Why it's wrong here
Storing IAM user access keys directly on an EC2 instance is a significant security vulnerability. These are long-term, static credentials that, if compromised, could grant an attacker persistent access to your AWS resources, potentially leading to data breaches or unauthorized operations. This method requires manual key rotation and violates AWS security best practices by hardcoding sensitive information, making it difficult to manage and secure at scale.
- ✗
Use root user credentials
Why it's wrong here
Using root user credentials for any programmatic access, especially on an EC2 instance, is an extremely dangerous security practice. The root user has unrestricted administrative access to the entire AWS account, bypassing all IAM policies applied to other users. A compromise of these credentials would grant an attacker full control over all resources, making it a critical security risk that violates the principle of least privilege and AWS's strong recommendations.
- ✓
Attach an IAM role with the required permissions to the EC2 instance
Why this is correct
Attaching an IAM role with the required permissions to an EC2 instance is the secure and recommended method for granting AWS services access to other AWS resources. When an IAM role is associated with an EC2 instance via an instance profile, the instance can automatically obtain temporary, frequently rotated credentials from the AWS Security Token Service (STS). This eliminates the need to embed or store static access keys on the instance, significantly reducing the risk of credential compromise and adhering to the principle of least privilege.
- ✗
Apply a service control policy (SCP) to the instance
Why it's wrong here
Applying a Service Control Policy (SCP) to an EC2 instance is incorrect because SCPs are a feature of AWS Organizations that define permission guardrails at the account or Organizational Unit (OU) level. SCPs establish the maximum available permissions for IAM users and roles within affected accounts, meaning they can restrict actions but cannot grant permissions directly to an individual EC2 instance. They act as a filter for what permissions *can* be granted, not as a mechanism to provide specific resource access.
Go deeper
Related to this question
About these practice questions
One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.