AWS Certified Security – SpecialtyDomain 3: Infrastructure SecurityEasy
A developer is configuring an AWS CodeDeploy deployment for an application running on EC2 instances. The deployment must ensure that the application's sensitive configuration files, stored in an Amazon S3 bucket, are securely downloaded to the instances during deployment. The S3 bucket is encrypted with SSE-KMS. What is the most secure way for the CodeDeploy agent on the EC2 instances to access these files?
- AEmbed S3 access keys directly into the CodeDeploy application specification (appspec.yml) for the agent to use.
- BGrant the EC2 instance's IAM role permissions to read from the S3 bucket and decrypt with the KMS key.
- CDisable S3 encryption temporarily during deployment to simplify access for the CodeDeploy agent.
- DConfigure a pre-install hook in the appspec.yml to use `aws s3 cp` with a pre-signed URL generated by a Lambda function.
Show answer & explanationAnswer & explanation
Correct answer: B. Grant the EC2 instance's IAM role permissions to read from the S3 bucket and decrypt with the KMS key.
Granting the EC2 instance's IAM role permissions to read from the S3 bucket and decrypt with the KMS key is the most secure and AWS-recommended practice. This leverages IAM roles for temporary, rotating credentials, adhering to the principle of least privilege.
Why the other options are wrong
- A. Embedding access keys is a severe security vulnerability and an anti-pattern in AWS.
- C. Disabling S3 encryption is a critical security breach and violates data protection standards for sensitive files.
- D. While pre-signed URLs provide temporary access, generating them via Lambda adds unnecessary complexity and management overhead compared to a direct IAM role permission for a recurring deployment task.
Secure EC2-S3 Access
Using IAM roles attached to EC2 instances to grant secure, temporary, and least-privilege access to AWS resources like S3 buckets and KMS keys.
- IAM roles provide temporary credentials.
- Principle of least privilege is applied.
- Eliminates hardcoding credentials.
Memory trick: EC2's S3 Key: IAM Roles, Not Hardcoded!