Courseiva

SAP-C02 Continuous Improvement for Existing Solutions Practice Question

A company has a web application running on Amazon EC2 instances in an Auto Scaling group. The application stores user-uploaded files in an Amazon S3 bucket. The company wants to improve the security of the application by ensuring that the EC2 instances can access the S3 bucket without embedding long-term AWS credentials in the application code or on the instances. Which solution meets these requirements with the LEAST operational overhead?

⚠ Common exam trap

The trap here is assuming that storing credentials in Secrets Manager or on an encrypted volume is secure enough, when the best practice is to avoid long-term credentials entirely by using IAM roles.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an IAM role with the necessary S3 permissions and attach it to the EC2 instances via an instance profile. The application uses the instance metadata service to obtain temporary credentials.

Attaching an IAM role to EC2 instances via an instance profile allows the application to obtain temporary credentials from the instance metadata service automatically. This eliminates the need to embed or manage long-term credentials, reduces operational overhead, and follows AWS security best practices. The other options either use long-term credentials, require secret management, or do not eliminate credential handling.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Generate a pre-signed URL for each file upload using AWS credentials stored in the application, and have the application provide the URL to users.

    Why it's wrong here

    Pre-signed URLs are useful for granting temporary access to specific objects, but they still require the application to have AWS credentials to generate them. If those credentials are long-term, the security risk remains. This does not eliminate the need for credentials on the instances and adds complexity for URL generation and expiration management. It does not meet the requirement of not embedding credentials.

  • ✗

    Create an IAM user with programmatic access and an access key, store the credentials in AWS Secrets Manager, and have the application retrieve them at startup.

    Why it's wrong here

    This approach still uses long-term credentials (IAM user access keys) and requires the application to retrieve and manage secrets. It adds operational overhead for rotation and secret management. It does not eliminate the need for credentials in the application, and IAM user access keys are not recommended for EC2 instances. The least operational overhead is to use IAM roles.

  • ✓

    Create an IAM role with the necessary S3 permissions and attach it to the EC2 instances via an instance profile. The application uses the instance metadata service to obtain temporary credentials.

    Why this is correct

    Attaching an IAM role to EC2 instances via an instance profile provides temporary credentials automatically rotated by AWS. The application can use the AWS SDK to retrieve credentials from the instance metadata service without embedding secrets. This is the least operational overhead because it requires no credential management and follows AWS best practices for secure access.

  • ✗

    Store the S3 bucket credentials in an encrypted Amazon EBS volume attached to each EC2 instance, and have the application read them from the volume.

    Why it's wrong here

    Storing credentials on an EBS volume is insecure and does not provide automatic rotation. It still requires managing long-term credentials and does not leverage AWS's temporary credential mechanisms. This approach adds operational overhead for volume management and does not meet the security best practice of using IAM roles. It also does not eliminate the need for credentials in the application.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 984 original SAP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.