SOA-C02 Security and Compliance Practice Question
A SysOps administrator needs to ensure that an EC2 instance can access an S3 bucket without storing AWS credentials on the instance. What should the administrator do?
⚠ Common exam trap
SOA-C02 often tests whether candidates know that IAM roles attached via instance profiles are the only secure way to grant EC2 access to AWS services, so options involving stored keys or IP-based policies are classic distractors.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an IAM role with S3 access and attach it to the instance profile.
The correct approach is to create an IAM role with the required S3 permissions and attach it to the EC2 instance profile, so the instance's SDK/CLI can retrieve temporary credentials from the instance metadata service (IMDS). This eliminates the need to store long-term AWS credentials on the instance and follows AWS best practices for least privilege and credential hygiene.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a bucket policy that allows access from the instance's public IP.
Why it's wrong here
Creating a bucket policy that grants access based on the instance's public IP is flawed because it addresses authorization on the bucket side without providing the instance any credentials to sign requests—the instance would still need IAM credentials to authenticate. Moreover, an EC2 instance's public IP can change or be shared via NAT, and IP-based conditions are less precise than IAM roles. AWS recommends using IAM roles or, for specific cases, bucket policies with principal conditions, not public IP ranges, because public IPs are not reliable identifiers for IAM authorization.
- ✓
Create an IAM role with S3 access and attach it to the instance profile.
Why this is correct
Attaching an IAM role to the EC2 instance via an instance profile is the secure, recommended way to grant S3 permissions. The instance automatically retrieves temporary security credentials from the instance metadata service (IMDS), which are rotated automatically, eliminating the need to embed long-lived access keys. The role's permissions policy (e.g., AmazonS3ReadOnlyAccess) defines exactly what S3 actions the instance can perform, and the instance profile is the container that delivers the role to the instance.
- ✗
Store the access key and secret key in a file on the instance.
Why it's wrong here
Storing the access key ID and secret access key in a file on the instance is a poor practice because it exposes long-lived static credentials that can easily leak through misconfigurations, malicious software, or accidental commits. These credentials do not automatically rotate and would remain valid even after the instance is terminated, creating a significant security risk. AWS strongly discourages this approach in favor of IAM roles, which are designed specifically for workloads running on EC2.
- ✗
Configure the security group to allow outbound traffic to S3.
Why it's wrong here
Configuring a security group to allow outbound traffic to S3 only controls network reachability at the instance's virtual firewall level; it does nothing to authenticate the instance or authorize S3 API operations. Without valid IAM credentials, the instance will still receive AccessDenied errors from S3. Security group rules apply only to network paths, whereas S3 permissions are evaluated by IAM policies, not by network access control.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.