AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceMedium

A developer's application running on an EC2 instance needs to call AWS APIs without embedding long-term access keys in the code. The application should receive short-lived credentials that automatically expire. Which AWS service or feature provides this capability?

  1. AAmazon Cognito Identity Pools only
  2. BAWS Certificate Manager
  3. CAWS Secrets Manager
  4. DAWS Security Token Service (STS)
Show answer & explanation

Correct answer: D. AWS Security Token Service (STS)

AWS STS issues temporary, limited-privilege security credentials for IAM users, federated users, or roles (such as an EC2 instance profile role). These credentials automatically expire, reducing the risk of long-term key exposure. ACM manages TLS certificates, not credentials; Secrets Manager stores and rotates secrets like database passwords, not general AWS API credentials.

Why the other options are wrong

  • A. Cognito Identity Pools use STS internally for mobile/web app federation but are not the general-purpose mechanism here.
  • B. ACM issues SSL/TLS certificates, unrelated to API credentials.
  • C. Secrets Manager stores and rotates application secrets, not IAM temporary credentials.

AWS STS

AWS Security Token Service issues temporary security credentials for IAM users and roles that automatically expire after a configured duration.

  • Underlies IAM roles including EC2 instance profiles
  • Credentials expire (default 1 hour, configurable)
  • Reduces risk versus long-term access keys

Memory trick: STS = 'Short Term Security' credentials

More Security and Compliance questions