SCS-C02 Infrastructure Security Practice Question
A company has an EC2 instance that needs to access an S3 bucket. The security team wants to use the principle of least privilege. Which method should be used to grant access?
⚠ Common exam trap
Candidates often confuse network-level controls (security groups) with IAM authorization, or mistakenly believe that an instance ID can be used as a principal in a bucket policy, which is not supported by AWS IAM.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an IAM role with an S3 access policy and attach it to the EC2 instance profile.
It follows the principle of least privilege by using an IAM role with a scoped S3 access policy, which is then attached to the EC2 instance profile. This allows the EC2 instance to obtain temporary security credentials from the AWS STS service, avoiding long-term access keys and ensuring permissions are granted only as needed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use a security group to allow outbound traffic to S3.
Why it's wrong here
Security groups are stateful network filters that control which traffic can reach or leave the instance, not which AWS API operations the instance is authorized to perform. Even if outbound HTTPS to S3 is allowed, the AWS SDK still needs valid credentials and an IAM policy permitting the specific S3 actions. This option only solves connectivity, leaving authentication and authorization unresolved.
- ✗
Store AWS access keys on the instance and use them in the application.
Why it's wrong here
Embedding long-lived AWS access keys in application code or on the instance disk creates a serious credential-leak risk; any process or attacker with read access can exfiltrate those keys and use them from outside the instance. These keys also require manual rotation and cannot be tightly scoped to the specific instance. IAM roles instead issue short-lived temporary credentials that are automatically rotated and assumed by the instance.
- ✓
Create an IAM role with an S3 access policy and attach it to the EC2 instance profile.
Why this is correct
Create an IAM role with a policy allowing the required S3 actions and attach that role to the EC2 instance via an instance profile. The instance then obtains temporary credentials from the instance metadata service, which are automatically rotated and used by the AWS SDK for signing S3 API requests. This is the secure, recommended pattern because it avoids persistent keys and follows least privilege.
- ✗
Create a bucket policy that grants access to the EC2 instance ID.
Why it's wrong here
Amazon S3 bucket policies are resource-based policies that can grant access to IAM principals such as users, roles, accounts, or federated principals, but never to EC2 instance IDs. An EC2 instance ID is not an IAM principal and is not present in the request's authorization context, so the policy condition would fail to match. To associate permissions with an instance, you must attach an IAM role to the instance profile and optionally use an aws:SourceArn condition.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.