SCS-C02 Identity and Access Management Practice Question
Which TWO are best practices for managing IAM roles for EC2 instances?
⚠ Common exam trap
Test-takers frequently confuse IAM user access key rotation (Option A) with role credential management, or think that storing keys directly on the instance (Option E) is acceptable if the instance is in a private subnet, but AWS explicitly recommends using IAM roles for EC2 to avoid hardcoded credentials.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Apply the principle of least privilege when defining role permissions.
The principle of least privilege ensures that an IAM role attached to an EC2 instance grants only the minimum permissions required for the application to function. This reduces the attack surface and limits potential damage from compromised instances. AWS Identity and Access Management (IAM) roles for EC2 use temporary security credentials obtained via the instance metadata service (IMDS), eliminating the need for long-term access keys.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Regularly rotate IAM user access keys.
Why it's wrong here
Rotating IAM user access keys is a hygiene measure for long-lived credentials attached to a user identity, not to an EC2 instance. It neither changes the permissions of the instance profile nor addresses how an application on the instance gains AWS access. Since instance roles issue ephemeral, automatically rotated credentials, periodic manual rotation of user access keys is irrelevant to this scenario.
- ✗
Attach the same role to all instances for simplicity.
Why it's wrong here
Attaching the same IAM role to every instance collapses the security boundary between different workloads. The role's policy would have to be the union of every application's requirements, creating unnecessarily broad permissions and making a compromise of any single instance expose all capabilities. It also prevents using resource-level conditions or scoped policies that distinguish environments, compliance boundaries, or application tiers.
- ✓
Apply the principle of least privilege when defining role permissions.
Why this is correct
Enforcing least privilege means granting only the specific API actions and resources required for the application's function, and then further constraining them with conditions such as ec2:ResourceTag or aws:SourceIp. This limits the blast radius if the instance is compromised because a breached application can only perform the minimal set of operations. A role's policy is the sole authority for what temporary credentials obtained through the instance profile can do, so its precision directly determines the security posture.
- ✓
Use an IAM role to grant permissions to applications running on EC2.
Why this is correct
An IAM role attached to an EC2 instance via an instance profile provides temporary security credentials through the instance metadata service (IMDSv2). The AWS SDK automatically retrieves, uses, and refreshes these credentials, so no long-term secrets ever need to be baked into the AMI or application code. This is the correct pattern because it relies on AWS-managed temporary credentials that automatically expire, reducing the risk of leaked static keys.
- ✗
Store AWS access keys directly on the instance.
Why it's wrong here
Storing AWS access keys directly on the instance leaves a permanent, unencrypted secret on the filesystem or in environment variables that can be stolen through an application vulnerability, misconfigured user-data script, or snapshot access. Unlike instance-profile credentials, these static access keys do not rotate automatically and remain valid until manually deleted, even after the instance is terminated. This pattern also forces you to manage and distribute the keys across every instance, whereas an instance profile removes that burden entirely.
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.