SOA-C02 Security and Compliance Practice Question
A SysOps administrator needs to provide temporary, limited-privilege credentials to an application running on an EC2 instance. The application needs to access an S3 bucket. What is the most secure way to grant these credentials?
⚠ Common exam trap
It's easy for candidates to think storing keys in environment variables or S3 is acceptable because it 'works', but the SOA-C02 exam specifically tests the understanding that IAM roles with EC2 instance profiles are the only secure, AWS-recommended method for providing temporary credentials to applications running on EC2, avoiding the pitfalls of long-term static keys.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Attach an IAM role with the necessary permissions to the EC2 instance.
Attaching an IAM role to an EC2 instance is the most secure method because it leverages the AWS Security Token Service (STS) to automatically rotate temporary credentials. The instance retrieves these credentials via the instance metadata service (IMDS), eliminating the need to hardcode, store, or manually manage long-term access keys. This approach follows the principle of least privilege and ensures credentials are automatically rotated and revoked when the role is detached.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use a Lambda function to generate temporary credentials from an IAM user.
Why it's wrong here
This approach still hinges on the IAM user's long-term access keys: the Lambda function must store or retrieve that user's secret key in order to call STS and produce temporary credentials. It merely moves the problem into a different compute service, leaving the same long-lived secret available to be leaked through environment variables or code. Additionally, the temporary credentials inherit all permissions of the user unless you attach a restrictive policy to the STS call, and you add unnecessary invocation overhead and cost.
- ✗
Store the AWS access keys in an S3 bucket and have the application download them at startup.
Why it's wrong here
Placing static access keys in an S3 object introduces a single point of exposure: if the bucket policy is misconfigured, the object is publicly readable, or the key is revealed through access logs, any party with read access can lift the credentials. The application still needs AWS credentials to download the object, creating a bootstrap dependency, and the keys remain valid indefinitely until manually rotated. This pattern also fails to provide the automatic rotation and least-privilege scoping that an IAM role would offer.
- ✓
Attach an IAM role with the necessary permissions to the EC2 instance.
Why this is correct
Attaching an IAM role to the EC2 instance via an instance profile is the AWS-recommended way to grant AWS API access to applications running on that instance. The AWS SDK and CLI automatically retrieve short-lived credentials from the instance metadata service (IMDSv2) and refresh them before they expire, so no secrets are stored in code, configuration, or environment variables. These credentials carry only the permissions defined in the role, and the role can be updated without changing the instance.
- ✗
Create an IAM user with programmatic access and store the access keys in the application's environment variables.
Why it's wrong here
Storing programmatic access keys in environment variables embeds long-term credentials in the runtime environment, which can be exposed by debugging tools, container inspection, or .env files that are accidentally committed to a repository. The keys are not rotated automatically and remain active even after the EC2 instance is terminated, creating an ongoing security liability. This also typically uses a single IAM user whose broad permissions violate least privilege, whereas an instance role would restrict access to only the required actions.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.