Courseiva
Design for New Solutions →mediumMultiple Select

SAP-C02 Design for New Solutions Practice Question

A company is designing a new application that will run on Amazon EC2 instances. The application needs to access an Amazon S3 bucket to read and write objects. The company wants to ensure that the EC2 instances can access the S3 bucket without storing AWS credentials on the instances. Which TWO steps should the company take?

⚠ Common exam trap

It's easy for candidates to confuse network-level controls (security group outbound rules) with authentication/authorization mechanisms, thinking that allowing outbound traffic to S3 is sufficient to grant access, when in fact the instance still needs valid IAM credentials to authenticate requests to S3.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Attach the IAM role to the EC2 instance profile.

Option A is correct because attaching an IAM role to the EC2 instance profile is the mechanism that delivers temporary, automatically rotated credentials to the instance via the instance metadata service (IMDS), so no long-term AWS credentials need to be stored on the instance. Option E is correct because the IAM role must first be created with a policy granting the specific S3 permissions (for example, s3:GetObject and s3:PutObject on the target bucket/prefix); without this role and policy, the instance profile would have nothing to assume. Option B is wrong because storing access keys in a configuration file on the instance is exactly the practice the company wants to avoid, and long-term keys are a security risk. Option C is wrong because an S3 bucket policy based on the EC2 instance's IP address is brittle and does not eliminate credentials; it also fails for instances behind NAT or with changing IPs. Option D is wrong because security groups control network reachability only and do not grant S3 authorization; outbound HTTPS to S3 is necessary but not sufficient, and it does not address credential-free access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Attach the IAM role to the EC2 instance profile.

    Why this is correct

    Attaching an IAM role to the EC2 instance profile lets the instance obtain temporary credentials from the instance metadata service automatically. The application then calls S3 using those rotating credentials, eliminating the need to store long-term AWS access keys on the instance.

  • ✗

    Store the AWS access key and secret access key in a configuration file on the instance.

    Why it's wrong here

    Embedding long-lived access keys in a file directly contradicts the requirement to avoid storing credentials on instances, and static keys cannot be rotated automatically. It is tempting because applications outside AWS, such as on-premises servers, genuinely authenticate this way; there, no instance metadata service exists to supply temporary role credentials.

  • ✗

    Create an S3 bucket policy that allows access from the EC2 instance's IP address.

    Why it's wrong here

    An IP-based bucket policy authorises requests by source address, not by instance identity, so it grants no credentials and breaks as soon as instances sit behind NAT or change address. It tempts because bucket policies are the standard mechanism for granting cross-account or anonymous public access to specific S3 resources.

  • ✗

    Configure the EC2 security group to allow outbound traffic to S3.

    Why it's wrong here

    Security groups filter network traffic only; permitting outbound TCP 443 to S3 does not authenticate the instance or grant any S3 permissions, so requests still fail with AccessDenied. It tempts because connectivity faults do block S3 access, and security group rules are the usual fix when an instance cannot reach an endpoint at all.

  • ✓

    Create an IAM role with a policy that grants the required S3 permissions.

    Why this is correct

    An IAM role attached to the instance profile lets the EC2 instance obtain temporary credentials from the instance metadata service, so no long-term AWS credentials are stored on the instance. The role's policy grants the required S3 permissions, satisfying the no-stored-credentials constraint.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 984 original SAP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.