Courseiva

SAA-C03 Design Secure Architectures Practice Question

A startup runs a public-facing web application on Amazon EC2 instances behind an Application Load Balancer. The application must call AWS APIs such as Amazon DynamoDB and Amazon S3. A security engineer must ensure that no long-term AWS credentials are stored on the instances and that each instance receives credentials automatically. Which solution should the engineer use?

⚠ Common exam trap

The trap here is treating an encrypted store such as Parameter Store or an encrypted EBS volume as sufficient, when the underlying problem is that the credentials themselves are long-lived rather than the storage medium.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Attach an IAM role for Amazon EC2 to an instance profile and associate it with each instance so the SDK retrieves temporary credentials from the instance metadata service.

Associating an IAM role with the instances through an instance profile lets the AWS SDK obtain temporary, automatically rotated credentials from the instance metadata service. This removes the need to store access keys on the instances, limits permissions to what the role allows, and satisfies the requirement that each instance receives credentials without manual handling.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Store an IAM user access key and secret key in AWS Systems Manager Parameter Store as a SecureString and retrieve them at instance boot.

    Why it's wrong here

    Parameter Store SecureString parameters are encrypted at rest, but they still contain long-term IAM user credentials. Those credentials do not rotate automatically, remain valid until manually deleted, and would be readable by anything that can call the parameter, which violates the requirement that no long-term credentials exist on the instances.

  • ✗

    Configure the instances to call AWS Security Token Service AssumeRole with a shared secret stored in an encrypted Amazon EBS volume.

    Why it's wrong here

    Calling AssumeRole requires some form of prior credential to sign the request, and storing a shared secret on an attached EBS volume simply relocates the long-term credential rather than removing it. Any process on the instance that can read the volume could impersonate the application, so the requirement for zero stored credentials is not met.

  • ✗

    Create an IAM user per instance, generate access keys, and rotate them every 90 days using a scheduled AWS Lambda function.

    Why it's wrong here

    This approach still places long-term access keys on each instance and adds operational complexity through a custom rotation function. If rotation fails or a key leaks between rotations, the credentials remain valid, and per-instance IAM users make permission management harder than using a single role with scoped policies.

  • ✓

    Attach an IAM role for Amazon EC2 to an instance profile and associate it with each instance so the SDK retrieves temporary credentials from the instance metadata service.

    Why this is correct

    An instance profile delivers temporary credentials through the instance metadata service, and the AWS SDK refreshes them automatically before they expire. No access keys are written to disk or configuration files, and permissions are controlled by the role's policies, so the design eliminates long-term credentials while granting least-privilege access to DynamoDB and S3.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 935 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.