SCS-C02 Identity and Access Management Practice Question
A solutions architect needs to design a system where an EC2 instance can write logs to CloudWatch Logs. Which IAM entity should be used to grant permissions to the EC2 instance?
⚠ Common exam trap
Candidates often confuse IAM groups with IAM roles, thinking a group can be attached to an EC2 instance, but groups only apply to IAM users and cannot be assumed by AWS services.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An IAM role with an instance profile
An IAM role with an instance profile is the correct approach because it allows the EC2 instance to assume temporary, rotated credentials via the AWS Security Token Service (STS). The instance profile is attached to the EC2 instance, and the AWS SDK or CLI automatically retrieves credentials from the instance metadata service (IMDS) to authenticate API calls to CloudWatch Logs. This eliminates the need to store long-term credentials on the instance and follows the principle of least privilege.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A resource-based policy on the EC2 instance
Why it's wrong here
EC2 instances are compute resources, not IAM principals, and they do not support resource-based policies. Resource-based policies can be attached to services such as S3 buckets, SNS topics, or KMS keys, but EC2 has no policy attachment point. To grant permissions to workloads running on an instance, you must use an IAM role through an instance profile.
- ✓
An IAM role with an instance profile
Why this is correct
An IAM role with an instance profile is the correct approach because it provides temporary credentials to the EC2 instance through the instance metadata service (IMDSv2). The EC2 service assumes the role on behalf of the instance, and the credentials are automatically rotated and never stored as static secrets on disk. This follows the AWS security best practice of using temporary credentials for all applications running on EC2.
- ✗
An IAM user with access keys stored on the instance
Why it's wrong here
Storing an IAM user's access keys on an EC2 instance is insecure because the keys are long-lived and remain valid indefinitely unless manually rotated. If the instance is compromised, an attacker can exfiltrate the keys and use them from anywhere. This also requires distributing secret material to every instance and managing key lifecycle, which is operationally fragile compared to the automatic, short-lived credentials provided by an instance profile.
- ✗
An IAM group
Why it's wrong here
IAM groups are administrative containers used to organize IAM users and attach policies to multiple users at once. Groups are not IAM principals and cannot be assigned to an EC2 instance or assumed by the EC2 service. The only valid way to grant permissions directly to an EC2 instance is through an IAM role embedded in an instance profile.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.