AWS Certified Security – SpecialtyDomain 4: Identity and Access ManagementEasy
A developer needs temporary credentials to access an Amazon S3 bucket from an EC2 instance. The EC2 instance is launched in a private subnet and does not have direct internet access. The credentials must be automatically rotated and follow the principle of least privilege. Which is the MOST secure and efficient way to provide these credentials?
- AGenerate long-lived IAM user access keys and store them as environment variables on the EC2 instance.
- BCreate an IAM user with S3 permissions, generate access keys, and securely transfer them to the EC2 instance via SSH.
- CEmbed the IAM user access keys directly into the application code running on the EC2 instance.
- DUse an IAM role attached to the EC2 instance and assign it the necessary S3 permissions.
Show answer & explanationAnswer & explanation
Correct answer: D. Use an IAM role attached to the EC2 instance and assign it the necessary S3 permissions.
Attaching an IAM role to an EC2 instance is the recommended and most secure way to provide temporary, automatically rotated credentials to applications running on the instance. The instance metadata service provides these credentials without storing them on the instance itself, adhering to the principle of least privilege.
Why the other options are wrong
- A. Long-lived access keys are a security risk as they do not automatically rotate and can be compromised. Storing them as environment variables is not secure.
- B. Manually creating an IAM user and transferring keys is cumbersome, less secure due to key management, and does not provide automatic rotation or follow the principle of least privilege as effectively as an IAM role.
- C. Embedding credentials in application code is a severe security anti-pattern. It exposes credentials and makes rotation and management extremely difficult.
IAM Roles for EC2
An IAM role that can be associated with an EC2 instance, allowing applications on the instance to securely make API calls to AWS services using temporary credentials.
- Provides temporary, automatically rotated credentials.
- Eliminates the need to store long-lived access keys on the instance.
- Credentials are retrieved via the EC2 instance metadata service.
- Enforces the principle of least privilege.
Memory trick: EC2 roles are the smart choice, no keys to voice.