AWS Certified Developer – Associate (DVA-C02)SecurityEasy
A development team is deploying a new web application on Amazon EC2 instances that needs to securely interact with other AWS services, such as Amazon S3 and Amazon DynamoDB, without embedding AWS access keys directly into the application code. The application runs on EC2 instances within a private subnet. Which method should the team use to grant these EC2 instances temporary, limited-privilege access to AWS resources?
- AUse AWS Secrets Manager to store the access keys and retrieve them at application startup.
- BGrant full administrator access to the EC2 instance's underlying IAM user.
- CGenerate IAM user access keys for each EC2 instance and store them on the instance.
- DCreate an IAM role, attach it to the EC2 instance profile, and assign the necessary permissions.
Show answer & explanationAnswer & explanation
Correct answer: D. Create an IAM role, attach it to the EC2 instance profile, and assign the necessary permissions.
Attaching an IAM role to an EC2 instance profile is the recommended and most secure way to grant permissions to applications running on EC2. It provides temporary credentials that are automatically rotated, eliminating the need to store static credentials on the instance.
Why the other options are wrong
- A. While Secrets Manager is good for secrets, it's not the primary mechanism for granting permissions to EC2 instances to call AWS APIs directly.
- B. Granting full administrator access violates the principle of least privilege and is a significant security vulnerability.
- C. Storing static IAM user access keys on EC2 instances is a security risk and is not recommended.
EC2 Instance Profiles and IAM Roles
An EC2 instance profile is a container for an IAM role that you can attach to an EC2 instance. This allows applications running on the instance to assume the role and gain temporary credentials for accessing other AWS services.
- Provides temporary, automatically rotated credentials.
- Eliminates the need to store static AWS credentials on the instance.
- Enforces the principle of least privilege.
Memory trick: Roles on Profiles Provide EC2 Power.