AWS Certified Security – SpecialtyDomain 4: Identity and Access ManagementEasy
A security engineer is designing an access strategy for a new application that will process highly sensitive customer data. The application runs on EC2 instances and needs to securely store temporary credentials for accessing an Amazon S3 bucket, an Amazon DynamoDB table, and an Amazon SQS queue. The credentials must be rotated frequently and should not be hardcoded into the application. Which AWS service and feature should the engineer use to meet these requirements?
- AEmbed access keys directly into the EC2 instance user data script during launch.
- BCreate IAM users with programmatic access keys for the application and store them in AWS Secrets Manager.
- CUse AWS Systems Manager Parameter Store to store and retrieve access keys for the application.
- DUtilize IAM roles for EC2 instances, attaching a role with necessary permissions to the instances.
Show answer & explanationAnswer & explanation
Correct answer: D. Utilize IAM roles for EC2 instances, attaching a role with necessary permissions to the instances.
IAM roles for EC2 instances provide a secure way for applications running on EC2 to obtain temporary credentials without hardcoding them. The credentials are automatically rotated by AWS, enhancing security.
Why the other options are wrong
- A. Embedding access keys directly into user data scripts is a highly insecure practice as it hardcodes long-lived credentials directly onto the instance.
- B. Storing programmatic access keys in Secrets Manager is better than hardcoding, but IAM roles for EC2 are more secure as they eliminate the need to manage long-lived credentials directly on the instance.
- C. Parameter Store can store sensitive data, but it typically stores long-lived credentials or configuration data. IAM roles provide temporary, automatically rotated credentials for EC2 instances, which is a more secure pattern for this use case.
IAM Roles for EC2
IAM roles for EC2 instances provide a mechanism for applications running on EC2 to securely obtain temporary credentials for making API requests to AWS services.
- Eliminates the need to hardcode credentials.
- Credentials are temporary and automatically rotated by AWS.
- Assigned to EC2 instances at launch or runtime.
Memory trick: EC2's Role is to be temporary and secure for the Cloud.