Courseiva

SAA-C03 Design Secure Architectures Practice Question

A company has an application running on Amazon EC2 instances that needs to access an Amazon S3 bucket. The security team wants to avoid storing long-term AWS credentials on the instances. Which solution should they implement?

⚠ Common exam trap

The trap here is thinking that Secrets Manager eliminates the need for credentials; it still requires managing and rotating secrets, whereas IAM roles provide temporary credentials automatically.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an IAM role with the necessary S3 permissions and attach it to the EC2 instances.

Attaching an IAM role to EC2 instances allows the instances to obtain temporary credentials from the instance metadata service. These credentials are automatically rotated and do not need to be stored on the instance. This eliminates the need for long-term credentials and is the recommended approach for granting AWS permissions to EC2 instances.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Generate an AWS access key and secret key for an IAM user and embed them in the application code.

    Why it's wrong here

    Embedding long-term credentials in application code is a security risk and directly contradicts the requirement. These credentials do not rotate automatically and can be exposed if the code is shared or the instance is compromised. This approach should be avoided.

  • ✗

    Store AWS credentials in a configuration file on each EC2 instance and restrict file permissions.

    Why it's wrong here

    Storing long-term credentials on EC2 instances is insecure and violates the requirement to avoid long-term credentials. Even with restricted file permissions, the credentials could be compromised if the instance is compromised. This approach does not use IAM roles and is not recommended by AWS.

  • ✓

    Create an IAM role with the necessary S3 permissions and attach it to the EC2 instances.

    Why this is correct

    Attaching an IAM role to EC2 instances provides temporary credentials that are automatically rotated. The instances can then access S3 without storing long-term credentials. This is the AWS best practice for granting permissions to EC2 instances and meets the requirement to avoid long-term credentials.

  • ✗

    Use AWS Secrets Manager to store the credentials and retrieve them at runtime.

    Why it's wrong here

    While Secrets Manager can store credentials securely, it still involves long-term credentials that need to be rotated and managed. It does not eliminate the need for credentials on the instance; the application must retrieve them. IAM roles are a more secure and seamless solution for EC2 instances, as they provide temporary credentials automatically.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.