QuestionQ52

Security and Compliance

An Amazon EC2 instance runs an application that uses Amazon Simple Queue Service (Amazon SQS) queues. A CloudOps engineer must make sure the application can read, write, and delete messages in the SQS queues.

Which solution meets these requirements in the MOST secure way?

Explanation

An IAM role associated with the EC2 instance supplies temporary credentials to the application without distributing long-term IAM user access keys. Limiting the role policy to sqs:SendMessage, sqs:ReceiveMessage, and sqs:DeleteMessage on the appropriate queues follows least privilege, whereas sqs:* grants unnecessary permissions.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!