SAA-C03 Design Secure Architectures Practice Question
A healthcare analytics company stores protected health information in an Amazon S3 bucket. An application running on Amazon EC2 instances in a private subnet must upload objects to the bucket using temporary credentials. The security team requires that the EC2 instances never store long-term AWS credentials on disk, and that access be limited to only the specific S3 bucket. Which solution meets these requirements?
⚠ Common exam trap
The trap here is assuming that storing long-term access keys in Secrets Manager converts them into temporary credentials.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Attach an IAM role to the EC2 instance profile with a policy granting s3:PutObject on the specific bucket, and let the AWS SDK retrieve temporary credentials automatically.
The requirement is temporary credentials without on-disk secrets, scoped to one bucket. An IAM role attached to the EC2 instance profile delivers rotating credentials through the instance metadata service, and the role's policy can be limited to the required S3 actions on the specific bucket. Long-term keys, presigned URLs, and IP-based policies do not satisfy the no-stored-credential and least-privilege conditions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure the S3 bucket policy to allow access from the EC2 instances' private IP addresses, and disable IAM authentication for the bucket.
Why it's wrong here
S3 bucket policies can restrict by source IP, but S3 requests are authenticated via IAM; disabling IAM authentication is not possible. Private IP addresses are not stable across instance replacement and are not a secure identity. This does not provide temporary credentials and would leave the bucket exposed to any principal that can spoof or share the address range.
- ✓
Attach an IAM role to the EC2 instance profile with a policy granting s3:PutObject on the specific bucket, and let the AWS SDK retrieve temporary credentials automatically.
Why this is correct
Attaching an IAM role to the instance profile allows the AWS SDK to obtain temporary credentials from the instance metadata service automatically. No long-term keys are stored on disk, and the attached policy can be scoped to grant only s3:PutObject on the specific bucket. This satisfies both the no-stored-credentials and least-privilege requirements with minimal operational overhead.
- ✗
Generate a presigned URL for each upload using a role with broad S3 permissions, and distribute the URLs to the EC2 instances.
Why it's wrong here
Presigned URLs are time-limited and useful for granting external parties temporary access, but they are not a credential mechanism for an application that initiates uploads on its own. Generating them requires an identity with permissions, and distributing them still requires a credential source on the instance. This approach also does not eliminate the need for the application to authenticate to AWS for other operations.
- ✗
Create an IAM user with an access key, store the key in AWS Secrets Manager, and configure the application to retrieve it at runtime.
Why it's wrong here
This still relies on long-term IAM user credentials, which the security team explicitly prohibits. Storing them in Secrets Manager only shifts the storage location; the access key remains valid until manually rotated, and if the instance is compromised the key can be exfiltrated. It also does not scope permissions to the specific bucket unless a custom policy is attached, adding complexity without meeting the no-long-term-credential requirement.
Visual reference
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 935 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.