SCS-C02 Identity and Access Management Practice Question
An application running on an EC2 instance needs to access an S3 bucket. What is the most secure way to grant the EC2 instance the necessary permissions?
⚠ Common exam trap
SCS-C02 often tests whether candidates understand that instance profiles provide temporary credentials via IMDS, not static keys — the trap is choosing 'encrypted credentials on disk' because it sounds secure, when it still involves long-lived secrets.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an IAM role with the necessary S3 permissions and attach it to the EC2 instance as an instance profile.
Attaching an IAM role to an EC2 instance via an instance profile delivers temporary, automatically rotated credentials through the Instance Metadata Service (IMDS), so no long-lived secrets exist on disk or in code. This is the AWS best practice for granting AWS service permissions to EC2 workloads and eliminates the risk of credential leakage.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create an IAM role with the necessary S3 permissions and attach it to the EC2 instance as an instance profile.
Why this is correct
Creating an IAM role with the necessary S3 permissions and attaching it as an instance profile is the AWS-recommended best practice. The EC2 instance receives temporary security credentials through the instance metadata service (IMDS), and the AWS SDKs automatically retrieve and refresh those credentials before they expire. This avoids storing any long-term keys on the instance, enforces least-privilege permissions scoped to the role, and gives you automatic rotation without manual intervention.
- ✗
Store the credentials in an encrypted file on the EC2 instance and decrypt them at runtime.
Why it's wrong here
Storing credentials in an encrypted file on the EC2 instance still means long-lived IAM user credentials are present on the local disk, and the decryption key must also be available on that same server for runtime use. If an attacker gains file system access or inspects memory, they can recover both the ciphertext and the key material. This approach also provides no automatic credential rotation or per-instance scoping, and the complexity of managing the encryption key makes it less secure than using an instance profile.
- ✗
Store the AWS access key and secret key in the application code.
Why it's wrong here
Hard-coding a long-term IAM access key and secret key into application code leaves static credentials that remain valid until manually revoked, even if they are leaked. These secrets commonly end up in source control history, build artifacts, or application logs, and rotating them requires modifying and redeploying code. Embedding keys in code also violates the least-privilege model because the same IAM user credentials could be used outside the application, so AWS recommends IAM roles instead.
- ✗
Use an S3 bucket policy that allows access from the EC2 instance's public IP address.
Why it's wrong here
Using an S3 bucket policy that allows access from the EC2 instance's public IP is not recommended because IP addresses can change (e.g., after stop/start) and it does not provide the principle of least privilege for the application.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.