Courseiva
Infrastructure Security →mediumMultiple Choice

SCS-C02 Infrastructure Security Practice Question

An application running on EC2 instances needs to access an S3 bucket. The Security Engineer wants to ensure that the EC2 instances do not have access keys and that the access is restricted to only the required bucket. What is the most secure way to provide this access?

⚠ Common exam trap

Test-takers frequently think storing access keys on the instance (Option A) is acceptable if the keys are scoped, but the exam emphasizes that any long-term credential on an instance is a security risk, and the IAM role mechanism is the only secure, AWS-native way to avoid hardcoded keys.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an IAM role with a policy that allows access to the specific S3 bucket, and attach the role to the EC2 instance profile.

It uses an IAM role attached to an EC2 instance profile, which allows the instance to obtain temporary security credentials from AWS STS (Security Token Service) without storing any long-term access keys. The role's policy can be scoped to grant access only to the specific S3 bucket, ensuring least privilege. This approach eliminates the risk of key exposure and is the AWS-recommended best practice for granting EC2 instances access to AWS services.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Generate an access key for an IAM user with permissions to the S3 bucket and store it in the EC2 instance.

    Why it's wrong here

    Generating a long-lived IAM access key and storing it on the EC2 instance is poor security practice because any process or user that compromises the instance can exfiltrate the static credentials and use them from anywhere. These keys do not expire, require manual rotation, and the application cannot distinguish between legitimate instance identity and malicious code running on the host. AWS recommends using temporary credentials delivered through an instance profile instead, which automatically rotate and reduce the exposure window if the instance is breached.

  • ✗

    Create an S3 bucket policy that allows the EC2 instance's public IP address to access the bucket.

    Why it's wrong here

    An S3 bucket policy cannot grant access to an EC2 instance merely by its public IP address because S3 requests must be authenticated with AWS Signature v4 credentials; the policy can only act as an authorization layer over an already-authenticated principal such as an IAM role or user. While it is possible to write a bucket policy that allows anonymous access from a specific IP, that still does not supply the application with the required signing keys, and the IP may be shared or dynamic. Moreover, relying on a network location rather than an AWS identity violates least privilege and does not scale for multi-instance architectures where every instance has its own security context.

  • ✓

    Create an IAM role with a policy that allows access to the specific S3 bucket, and attach the role to the EC2 instance profile.

    Why this is correct

    Creating an IAM role with a narrowly scoped policy and attaching it as the instance profile lets the EC2 instance securely obtain temporary credentials from AWS STS through the instance metadata service, with no keys embedded in the AMI or stored on disk. These credentials are rotated automatically and are valid only for a short duration, reducing the blast radius of any credentials leak. The policy can restrict actions to the specific S3 bucket (for example, s3:GetObject and s3:ListBucket), and the role's trust policy allows the EC2 service to assume it, ensuring the instance operates with least privilege and a clear audit trail in CloudTrail.

  • ✗

    Use the root user's access keys to configure the application.

    Why it's wrong here

    AWS root user access keys are unrestricted master credentials that provide full administrative access to the entire account, so embedding them in an application is a catastrophic security risk because they cannot be scoped down to only the target S3 bucket. AWS best practice is to remove root user access keys entirely and instead use IAM roles or dedicated IAM users with only the necessary permissions. Additionally, root user keys are static, are not rotated automatically, and cannot be limited by service, resource, or condition, making them completely unsuitable for an EC2 workload.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.