An Amazon EC2 instance runs an application that uses Amazon Simple Queue Service (Amazon SQS) queues. A CloudOps engineer must make sure the application can read, write, and delete messages in the SQS queues.
Which solution meets these requirements in the MOST secure way?
A Create an IAM user with an IAM policy that allows the sqs:SendMessage permission, the sqsReceiveMessage permission, and the sqs:DeleteMessage permission to the appropriate queues. Embed the IAM user's credentials in the application’s configuration. B Create an IAM user with an IAM policy that allows the sqs:SendMessage permission, the sqs:ReceiveMessage permission, and the sqs:DeleteMessage permission to the appropriate queues. Export the IAM user's access key and secret access key as environment variables on the EC2 instance. C Create and associate an IAM role that allows EC2 instances to call AWS services. Attach an IAM policy to the role that allows sqs:* permissions to the appropriate queues. D Create and associate an IAM role that allows EC2 instances to call AWS services. Attach an IAM policy to the role that allows the sqs:SendMessage permission, the sqs:ReceiveMessage permission, and the sqs:DeleteMessage permission to the appropriate queues. Show Answer Answer Explanation An IAM role associated with the EC2 instance supplies temporary credentials to the application without distributing long-term IAM user access keys. Limiting the role policy to sqs:SendMessage, sqs:ReceiveMessage, and sqs:DeleteMessage on the appropriate queues follows least privilege, whereas sqs:* grants unnecessary permissions.
Learn more
Community Discussion