AWS Certified DevOps Engineer – ProfessionalSecurity and ComplianceMedium

A DevOps team is deploying a containerized application to Amazon ECS. The application needs to interact with various AWS services, such as DynamoDB and SQS. The security team insists that the application containers should never have hardcoded AWS credentials and must adhere to the principle of least privilege. What is the most secure and recommended way to grant AWS permissions to the ECS tasks running the application containers?

  1. AEmbed AWS credentials in a configuration file within the container and encrypt it with KMS.
  2. BDefine an IAM role for the ECS task and associate it with the task definition.
  3. CStore AWS access keys in environment variables within the Docker image.
  4. DUse an EC2 instance profile attached to the underlying ECS instances.
Show answer & explanation

Correct answer: B. Define an IAM role for the ECS task and associate it with the task definition.

Defining an IAM role for the ECS task (Task IAM Role) and associating it with the task definition is the most secure and recommended method. This allows each task to assume a specific role with fine-grained permissions, providing least privilege and eliminating the need to embed credentials within the container or on the host EC2 instance.

Why the other options are wrong

  • A. Embedding credentials, even encrypted, is less secure than using IAM roles which provide temporary, automatically rotated credentials.
  • C. Storing credentials in environment variables is highly insecure and violates best practices.
  • D. An EC2 instance profile grants permissions to all tasks running on that instance, violating least privilege if tasks have different needs. It's less granular than a task IAM role.

ECS Task IAM Roles

An AWS IAM role that you can associate with an Amazon ECS task definition to grant specific permissions to the containers within that task.

  • Provides granular, least-privilege access to AWS services for tasks.
  • Eliminates the need for hardcoded credentials.
  • Credentials are automatically managed and rotated by AWS.

Memory trick: Each ECS Task gets its own IAM 'badge' for specific access.

More Security and Compliance questions