AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceMedium
A developer's application running on an EC2 instance needs to call AWS APIs without embedding long-term access keys in the code. The application should receive short-lived credentials that automatically expire. Which AWS service or feature provides this capability?
- AAmazon Cognito Identity Pools only
- BAWS Certificate Manager
- CAWS Secrets Manager
- DAWS Security Token Service (STS)
Show answer & explanationAnswer & explanation
Correct answer: D. AWS Security Token Service (STS)
AWS STS issues temporary, limited-privilege security credentials for IAM users, federated users, or roles (such as an EC2 instance profile role). These credentials automatically expire, reducing the risk of long-term key exposure. ACM manages TLS certificates, not credentials; Secrets Manager stores and rotates secrets like database passwords, not general AWS API credentials.
Why the other options are wrong
- A. Cognito Identity Pools use STS internally for mobile/web app federation but are not the general-purpose mechanism here.
- B. ACM issues SSL/TLS certificates, unrelated to API credentials.
- C. Secrets Manager stores and rotates application secrets, not IAM temporary credentials.
AWS STS
AWS Security Token Service issues temporary security credentials for IAM users and roles that automatically expire after a configured duration.
- Underlies IAM roles including EC2 instance profiles
- Credentials expire (default 1 hour, configurable)
- Reduces risk versus long-term access keys
Memory trick: STS = 'Short Term Security' credentials