QuestionQ3

Identity and Access Management

A company hosts an application on an Amazon EC2 instance. The application creates invoices and saves them in an Amazon S3 bucket. The instance profile attached to the instance has the required access to the S3 bucket.

The company must share every invoice with multiple clients who do not have AWS credentials. Each client must be able to download only that client’s own invoices. Clients must download invoices within 1 hour after invoice creation. Clients must use only temporary credentials to access the company’s AWS resources.

A security engineer creates a script that runs on the EC2 instance. The script uses the instance profile to create an S3 presigned URL for the clients. Each presigned URL expires after 1 hour.

Which additional step will satisfy these requirements?

Explanation

AWS STS AssumeRole returns temporary security credentials. Presigning each invoice’s S3 GetObject request with newly assumed-role credentials grants access only to the specific object identified by that URL and limits access to the URL’s configured one-hour lifetime. The clients need no IAM user credentials or broader S3 permissions.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!