SAA-C03 Design Secure Architectures Practice Question
A company has an application running on Amazon EC2 instances that needs to access an Amazon S3 bucket. The security team wants to avoid storing long-term AWS credentials on the instances. Which solution should they implement?
⚠ Common exam trap
The trap here is thinking that Secrets Manager eliminates the need for credentials; it still requires managing and rotating secrets, whereas IAM roles provide temporary credentials automatically.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an IAM role with the necessary S3 permissions and attach it to the EC2 instances.
Attaching an IAM role to EC2 instances allows the instances to obtain temporary credentials from the instance metadata service. These credentials are automatically rotated and do not need to be stored on the instance. This eliminates the need for long-term credentials and is the recommended approach for granting AWS permissions to EC2 instances.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Generate an AWS access key and secret key for an IAM user and embed them in the application code.
Why it's wrong here
Embedding long-term credentials in application code is a security risk and directly contradicts the requirement. These credentials do not rotate automatically and can be exposed if the code is shared or the instance is compromised. This approach should be avoided.
- ✗
Store AWS credentials in a configuration file on each EC2 instance and restrict file permissions.
Why it's wrong here
Storing long-term credentials on EC2 instances is insecure and violates the requirement to avoid long-term credentials. Even with restricted file permissions, the credentials could be compromised if the instance is compromised. This approach does not use IAM roles and is not recommended by AWS.
- ✓
Create an IAM role with the necessary S3 permissions and attach it to the EC2 instances.
Why this is correct
Attaching an IAM role to EC2 instances provides temporary credentials that are automatically rotated. The instances can then access S3 without storing long-term credentials. This is the AWS best practice for granting permissions to EC2 instances and meets the requirement to avoid long-term credentials.
- ✗
Use AWS Secrets Manager to store the credentials and retrieve them at runtime.
Why it's wrong here
While Secrets Manager can store credentials securely, it still involves long-term credentials that need to be rotated and managed. It does not eliminate the need for credentials on the instance; the application must retrieve them. IAM roles are a more secure and seamless solution for EC2 instances, as they provide temporary credentials automatically.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.