Courseiva
Design Secure Architectures →mediumMultiple Choice

SAA-C03 Design Secure Architectures Practice Question

A web application hosted on EC2 instances needs to access a DynamoDB table. What is the most secure way to provide the application with the necessary permissions?

⚠ Common exam trap

SAA-C03 often tests whether candidates default to IAM roles for AWS service access; the trap is choosing stored access keys or root credentials, which are insecure and operationally burdensome compared to instance profiles.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Attach an IAM role to the EC2 instance profile.

Attaching an IAM role to the EC2 instance profile provides temporary, automatically rotated credentials to the application via the instance metadata service, eliminating the need to store long-term keys. This is the AWS-recommended, most secure way to grant EC2-hosted applications access to DynamoDB.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Store IAM access keys in a configuration file on the EC2 instance.

    Why it's wrong here

    Storing static keys on an EC2 instance is a significant security risk. If the instance is compromised, the attacker can extract the keys and gain permanent access to the AWS account. Furthermore, managing the lifecycle and rotation of these keys creates unnecessary manual work and potential for security drift.

  • ✓

    Attach an IAM role to the EC2 instance profile.

    Why this is correct

    IAM roles provide temporary security credentials that are automatically rotated by AWS. By attaching a role to the EC2 instance, the application gains the necessary permissions without the need for static credentials, which is the industry standard for secure service-to-service authentication and authorization within the AWS ecosystem.

  • ✗

    Assign the EC2 instance a public IP address.

    Why it's wrong here

    A public IP address is a networking configuration, not an authentication or authorization mechanism. It provides no security benefit for accessing DynamoDB and actually exposes the instance to potential inbound internet traffic. Security should be managed through IAM policies, not by modifying network accessibility or IP address allocation.

  • ✗

    Use the root user credentials for the application.

    Why it's wrong here

    Using root credentials is a severe violation of security best practices. The root user has full, unrestricted access to the entire AWS account. If an application is compromised, the entire account, including all resources and billing information, is at risk. Never use root credentials for any programmatic application access.

About these practice questions

This SAA-C03 question is part of Courseiva's 149-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.