AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceEasy
A startup runs an application on Amazon EC2 that needs to read objects from an S3 bucket. The security team wants to avoid storing long-term access keys on the instance. What should the team do?
- ACreate an IAM group and add the EC2 instance as a member
- BAttach an IAM role with the required S3 permissions to the EC2 instance
- CEmbed the root user's credentials in the application code
- DStore an IAM user's access key and secret key in a configuration file on the instance
Show answer & explanationAnswer & explanation
Correct answer: B. Attach an IAM role with the required S3 permissions to the EC2 instance
IAM roles provide temporary, automatically rotated credentials to AWS resources like EC2 instances, eliminating the need to store long-term access keys. This is the AWS-recommended way to grant permissions to applications running on EC2.
Why the other options are wrong
- A. IAM groups are for organizing users, not for attaching to EC2 instances.
- C. Root credentials should never be used for application access.
- D. Long-term keys on disk are a security risk and against best practice.
IAM Role for EC2 (Instance Profile)
An IAM role attached to an EC2 instance that supplies temporary security credentials to applications running on it, avoiding hard-coded keys.
- Credentials rotate automatically
- Assigned via an instance profile
- Best practice over embedding access keys
Memory trick: Roles rent credentials, users own them.