Courseiva
Security and Compliance →hardMultiple Choice

SOA-C02 Security and Compliance Practice Question

An application running on Amazon EC2 needs to access an S3 bucket. The SysOps administrator wants to ensure that only that specific EC2 instance can access the bucket, without storing any long-term credentials on the instance. What is the most secure way to achieve this?

⚠ Common exam trap

SOA-C02 often tests the misconception that storing credentials in user data or using pre-signed URLs is 'secure enough' — the exam expects recognition that IAM roles with instance profiles and IMDSv2 are the only best-practice answer for EC2-to-S3 access without long-term credentials.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Attach an IAM role to the EC2 instance using an instance profile and grant the role S3 access

Attaching an IAM role to the EC2 instance via an instance profile allows the instance to obtain temporary credentials from the EC2 Instance Metadata Service (IMDS), which are automatically rotated. This eliminates the need to store long-term access keys on the instance and scopes permissions to the specific role. It is the AWS-recommended best practice for granting EC2 access to S3.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Attach an IAM role to the EC2 instance using an instance profile and grant the role S3 access

    Why this is correct

    Attaching an IAM role to the EC2 instance through an instance profile is the AWS best practice because the instance retrieves temporary security credentials from the instance metadata service. These credentials are automatically rotated by AWS, eliminating the need to store or manage long-term access keys on the instance. The role's identity-based policy grants the instance exactly the S3 permissions required, following the principle of least privilege.

  • ✗

    Configure a resource-based policy on the EC2 instance to allow S3 access

    Why it's wrong here

    EC2 instances do not support resource-based policies; IAM policies that grant permissions to an instance must be identity-based and attached to an IAM role. Resource-based policies are used with services like S3 buckets, SQS queues, and KMS keys, where the resource owner explicitly defines who can access the resource. Since an EC2 instance is not a resource that can have a separate policy attached, this option is invalid.

  • ✗

    Create an IAM user with S3 access and store the access keys in the instance's user data

    Why it's wrong here

    Storing IAM user access keys in instance user data is a significant security risk because user data is visible to anyone with access to the instance metadata service or the EC2 console. Long-term credentials embedded this way are not automatically rotated and could be exposed if the instance is compromised or the user data is misconfigured. IAM roles with temporary credentials are the secure alternative and avoid placing permanent secrets on the instance.

  • ✗

    Generate pre-signed URLs for each S3 object the application needs to access

    Why it's wrong here

    Pre-signed URLs provide time-limited access to individual S3 objects and are typically used to grant temporary access to a specific object without requiring AWS credentials. For an application that needs ongoing access to an entire S3 bucket, managing pre-signed URLs for every object would be impractical and prone to expiration or permission errors. Additionally, generating pre-signed URLs still requires the application to have valid AWS credentials, which brings back the underlying authentication and authorization problem.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on SOA-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A SysOps administrator needs to ensure that an Amazon EC2 instance can access an Amazon S3 bucket without storing long-term credentials on the instance. Which approach should be used?

easy
  • A.Configure a security group rule that allows outbound traffic to S3.
  • B.Assign a bucket policy that grants access to the EC2 instance's public IP address.
  • ✓ C.Create an IAM role with S3 permissions and attach it to the EC2 instance profile.
  • D.Create an IAM user with programmatic access and store the credentials in a file on the instance.

Why C: Attaching an IAM role to an EC2 instance profile allows the instance to obtain temporary security credentials from the instance metadata service, eliminating the need to store long-term credentials on the instance. Option A is incorrect because security groups control network traffic, not API-level access to S3. Option B is incorrect because a bucket policy granting access based on a public IP address is insecure and does not provide AWS credentials. Option D is incorrect because storing IAM user credentials on the instance is insecure and not a best practice.

Variation 2. A SysOps administrator is investigating why an EC2 instance cannot access an S3 bucket using an IAM role. The instance has an associated IAM role with a policy that allows s3:GetObject on the bucket. The bucket policy also allows access from the role. However, the instance's application still gets access denied. What is the most likely cause?

medium
  • A.The IAM role does not have s3:ListBucket permission
  • ✓ B.The IAM role is not associated with the instance profile used by the EC2 instance
  • C.The bucket policy explicitly denies access to the role
  • D.The S3 bucket is in a different region, requiring a VPC endpoint

Why B: The most likely cause is that the IAM role is not properly associated with the instance profile used by the EC2 instance. For an EC2 instance to use an IAM role, the role must be attached to an instance profile, and that instance profile must be associated with the instance. Without this association, the instance lacks credentials to assume the role. Option A is incorrect because s3:GetObject does not require ListBucket permission unless the application needs to list objects. Option C is incorrect because the bucket policy allows access from the role, so an explicit deny is not the issue. Option D is incorrect because cross-region access to S3 does not require a VPC endpoint; the instance can access S3 over the internet.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.