SOA-C02 Security and Compliance Practice Question
A company wants to ensure that an EC2 instance can access an S3 bucket without storing AWS credentials on the instance. What should the SysOps administrator do?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an IAM role with permissions to the S3 bucket and attach it to the EC2 instance profile.
An IAM role can be attached to an EC2 instance via an instance profile, granting temporary security credentials that allow the instance to access the S3 bucket without storing long-term credentials on the instance. Option B is incorrect because an S3 bucket policy cannot be attached to an instance; it is attached to the S3 bucket itself, and using the instance's public IP is not a secure or recommended method. Option C is incorrect because storing access keys on the instance violates the requirement of not storing credentials. Option D is incorrect because while AWS STS can generate temporary credentials, storing them in instance user data is not secure and does not eliminate credential storage on the instance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create an IAM role with permissions to the S3 bucket and attach it to the EC2 instance profile.
Why this is correct
Attaching an IAM role to an EC2 instance through an instance profile is the secure, AWS-recommended approach. The instance profile is passed to the instance at launch, and the Amazon EC2 service uses the role's trust policy to call the AWS Security Token Service (STS) to issue short-term credentials that are delivered via the instance metadata service. These credentials are automatically rotated by the EC2 service before they expire, so the application can access the S3 bucket without ever storing or handling secrets.
- ✗
Attach an S3 bucket policy that grants access to the EC2 instance's public IP address.
Why it's wrong here
An S3 bucket policy is a resource-based policy that lives on the bucket itself and controls access to all principals; it cannot be attached to an EC2 instance. Moreover, restricting access by public IP address is unreliable because an instance's public IP can change after a stop/start, and such a condition does not authenticate the instance's identity or its IAM context. AWS recommends using IAM roles with instance profiles so the bucket policy can reference the IAM role ARN, not the instance's IP.
- ✗
Generate access keys for an IAM user and store them on the instance.
Why it's wrong here
Generating long-term access keys for an IAM user and placing them on the instance leaks long-lived, static credentials that never expire and are not automatically rotated. Any process or user that gains access to the instance filesystem (or user data, if placed there) could read the secret key and impersonate that IAM user, breaching the principle of least privilege. Modern best practice is to deploy IAM roles for EC2 so that each instance dynamically receives short-lived credentials via instance metadata, which removes the need to store any secret material on disk.
- ✗
Use AWS STS to generate temporary credentials and store them in the instance's user data.
Why it's wrong here
Temporary credentials from AWS STS are short-lived, typically expiring after anywhere from 15 minutes to 36 hours depending on the session duration, so using them as a persistent authorization mechanism for an instance would cause intermittent access failures and require a separate, long-lived credential to regenerate them. Storing them in instance user data is especially problematic because user data is visible in plain text to anyone with the ability to describe the instance, and it is only available at launch time. This approach combines the inconvenience of expiration with a new security risk, making it far less secure than attaching an IAM role to the instance profile.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.