Courseiva

SAA-C03 Design Secure Architectures Practice Question

An application running on an Amazon EC2 instance needs to securely access data in an Amazon DynamoDB table. What is the most secure way to provide the application with the necessary permissions?

⚠ Common exam trap

SAA-C03 often tests the misconception that storing credentials in environment variables or configuration files is acceptable for security, when in fact IAM roles are the only secure, AWS-recommended method for EC2-to-AWS-service authentication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an IAM role with the required permissions and attach it to the EC2 instance profile.

IAM roles attached to an EC2 instance profile provide temporary, automatically rotated credentials to the instance via the Instance Metadata Service (IMDS). The application (or AWS SDK) retrieves these credentials without any hardcoded secrets, and permissions are managed centrally through IAM policies. This eliminates the risk of long-term credential leakage and follows AWS best practices for least privilege.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Store IAM user credentials in a configuration file on the EC2 instance.

    Why it's wrong here

    Storing long-term credentials in configuration files is a significant security risk, as anyone with access to the file system can compromise the account. If the instance is breached or the code is shared, the credentials could be used maliciously to access sensitive data across the AWS environment.

  • ✓

    Create an IAM role with the required permissions and attach it to the EC2 instance profile.

    Why this is correct

    Attaching an IAM role to an EC2 instance allows the application to use temporary security credentials provided by the Instance Metadata Service. This eliminates the need to hardcode or store long-term keys, adhering to the principle of least privilege and significantly improving the overall security posture.

  • ✗

    Pass the Access Key and Secret Key as environment variables when starting the application.

    Why it's wrong here

    Using environment variables to store credentials is slightly better than configuration files but still leaves the keys vulnerable to exposure through process monitoring tools or logs. This method still relies on long-term credentials that must be manually rotated, which increases the operational burden and risk.

  • ✗

    Embed the credentials directly into the application source code.

    Why it's wrong here

    Hardcoding credentials into source code is one of the most dangerous security practices. If the code is pushed to a version control system like GitHub, the credentials can be easily discovered by unauthorized parties, leading to full account compromise and potential data theft from the DynamoDB table.

About these practice questions

This SAA-C03 question is part of Courseiva's 149-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.