QuestionQ315

Content Domain 2: Security and Compliance

According to security best practices, how should an Amazon EC2 instance receive access to an Amazon S3 bucket?

  • A Hard code an IAM user’s secret key and access key directly in the application, and upload the file.
  • B Store the IAM user’s secret key and access key in a text file on the EC2 instance, read the keys, then upload the file.
  • C Have the EC2 instance assume a role to obtain the privileges to upload the file.
  • D Modify the S3 bucket policy so that any service can upload to it at any time.
Explanation

An EC2 instance should use an IAM role attached through an instance profile to obtain temporary credentials and only the S3 permissions it needs. This avoids exposing or managing long-term IAM user access keys in application code or files on the instance.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!