SOA-C02 Security and Compliance Practice Question
A SysOps administrator needs to ensure that an Amazon EC2 instance can access an Amazon S3 bucket without storing long-term credentials on the instance. Which approach should be used?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an IAM role with S3 permissions and attach it to the EC2 instance profile.
Attaching an IAM role to an EC2 instance profile allows the instance to obtain temporary security credentials from the instance metadata service, eliminating the need to store long-term credentials on the instance. Option A is incorrect because security groups control network traffic, not API-level access to S3. Option B is incorrect because a bucket policy granting access based on a public IP address is insecure and does not provide AWS credentials. Option D is incorrect because storing IAM user credentials on the instance is insecure and not a best practice.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure a security group rule that allows outbound traffic to S3.
Why it's wrong here
A security group acts as a virtual stateful firewall at the instance network interface level, filtering traffic by IP, protocol, and port. While allowing outbound HTTPS to S3 IP ranges would permit a TCP connection, the S3 API requires authenticated requests signed with AWS credentials (SigV4) that the instance has no way to generate without an IAM role or user. Therefore, this rule addresses connectivity only, not the identity and authorization needed to list, read, or write objects.
- ✗
Assign a bucket policy that grants access to the EC2 instance's public IP address.
Why it's wrong here
A bucket policy is a resource-based policy that can include a condition like aws:SourceIp to restrict access to a specific public IP, but the policy alone does not supply the EC2 instance with an identity to authenticate. The instance must still present valid AWS credentials as a principal (e.g., an IAM role) to sign the API request; a public IP address is merely a network attribute and not a substitute for authentication. Moreover, public IPs can change or be shared via NAT, making this an unreliable control.
- ✓
Create an IAM role with S3 permissions and attach it to the EC2 instance profile.
Why this is correct
Attaching an IAM role to the EC2 instance via an instance profile is the AWS-recommended approach because it provides the instance with temporary, rotated credentials automatically. The instance retrieves these credentials from the instance metadata service (IMDSv2) after assuming the role, and the AWS SDK on the instance automatically uses them to sign S3 API requests without any hard-coded keys. This follows least privilege and eliminates the operational burden of key management on the instance.
- ✗
Create an IAM user with programmatic access and store the credentials in a file on the instance.
Why it's wrong here
Creating an IAM user with programmatic access and storing its access key ID and secret access key on the instance exposes long-term credentials that do not rotate and can be exfiltrated if the instance is compromised or the file is read. This violates the best practice of using IAM roles for EC2, because the credentials remain valid even after the instance is terminated unless manually revoked by an administrator. It also requires secure key distribution and periodic rotation, adding complexity and risk.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.