Courseiva
Design Secure Architectures →mediumMultiple Choice

SAA-C03 Design Secure Architectures Practice Question

A healthcare analytics company stores protected health information in an Amazon S3 bucket. An application running on Amazon EC2 instances in a private subnet must upload objects to the bucket using temporary credentials. The security team requires that the EC2 instances never store long-term AWS credentials on disk, and that access be limited to only the specific S3 bucket. Which solution meets these requirements?

⚠ Common exam trap

The trap here is assuming that storing long-term access keys in Secrets Manager converts them into temporary credentials.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Attach an IAM role to the EC2 instance profile with a policy granting s3:PutObject on the specific bucket, and let the AWS SDK retrieve temporary credentials automatically.

The requirement is temporary credentials without on-disk secrets, scoped to one bucket. An IAM role attached to the EC2 instance profile delivers rotating credentials through the instance metadata service, and the role's policy can be limited to the required S3 actions on the specific bucket. Long-term keys, presigned URLs, and IP-based policies do not satisfy the no-stored-credential and least-privilege conditions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure the S3 bucket policy to allow access from the EC2 instances' private IP addresses, and disable IAM authentication for the bucket.

    Why it's wrong here

    S3 bucket policies can restrict by source IP, but S3 requests are authenticated via IAM; disabling IAM authentication is not possible. Private IP addresses are not stable across instance replacement and are not a secure identity. This does not provide temporary credentials and would leave the bucket exposed to any principal that can spoof or share the address range.

  • ✓

    Attach an IAM role to the EC2 instance profile with a policy granting s3:PutObject on the specific bucket, and let the AWS SDK retrieve temporary credentials automatically.

    Why this is correct

    Attaching an IAM role to the instance profile allows the AWS SDK to obtain temporary credentials from the instance metadata service automatically. No long-term keys are stored on disk, and the attached policy can be scoped to grant only s3:PutObject on the specific bucket. This satisfies both the no-stored-credentials and least-privilege requirements with minimal operational overhead.

  • ✗

    Generate a presigned URL for each upload using a role with broad S3 permissions, and distribute the URLs to the EC2 instances.

    Why it's wrong here

    Presigned URLs are time-limited and useful for granting external parties temporary access, but they are not a credential mechanism for an application that initiates uploads on its own. Generating them requires an identity with permissions, and distributing them still requires a credential source on the instance. This approach also does not eliminate the need for the application to authenticate to AWS for other operations.

  • ✗

    Create an IAM user with an access key, store the key in AWS Secrets Manager, and configure the application to retrieve it at runtime.

    Why it's wrong here

    This still relies on long-term IAM user credentials, which the security team explicitly prohibits. Storing them in Secrets Manager only shifts the storage location; the access key remains valid until manually rotated, and if the instance is compromised the key can be exfiltrated. It also does not scope permissions to the specific bucket unless a custom policy is attached, adding complexity without meeting the no-long-term-credential requirement.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 935 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.