AWS Certified Developer – Associate (DVA-C02)SecurityEasy
A developer is building an application that needs to retrieve temporary security credentials to make programmatic calls to AWS services. The application is running on an EC2 instance. Which mechanism should the developer use to obtain these credentials securely without embedding them in the application code or configuration files?
- AGenerate temporary credentials using AWS CLI on the EC2 instance and store them in local files.
- BUse an IAM role for EC2 instance and retrieve credentials from the instance metadata service.
- CStore the IAM user's access key and secret key in an S3 bucket and retrieve them at runtime.
- DCreate a new IAM user specifically for the EC2 instance and configure it with long-term credentials.
Show answer & explanationAnswer & explanation
Correct answer: B. Use an IAM role for EC2 instance and retrieve credentials from the instance metadata service.
Using an IAM role for an EC2 instance is the recommended and most secure way to provide AWS credentials to applications running on that instance. The application can then retrieve temporary, regularly rotated credentials from the instance metadata service (IMDS) without ever storing long-term credentials.
Why the other options are wrong
- A. Storing temporary credentials in local files still involves managing their lifecycle and rotation, and is less secure than using IMDS with an IAM role.
- C. Storing credentials, even in S3, is a security risk and requires additional access management for the S3 bucket itself.
- D. Creating an IAM user with long-term credentials for an EC2 instance is insecure and goes against AWS best practices for providing credentials to compute resources.
EC2 Instance Profiles & IAM Roles
An EC2 instance profile is a container for an IAM role that allows EC2 instances to obtain temporary, programmatic access to AWS services using the instance metadata service.
- Provides temporary, auto-rotated credentials.
- Eliminates the need to store long-term credentials on the instance.
- Credentials are retrieved via the Instance Metadata Service (IMDS).
Memory trick: Instance Roles give temporary keys via IMDS.