During a credential review, a CloudOps engineer finds that an application running on an EC2 instance reads an IAM user's access keys from a configuration file to call Amazon S3. What is the MOST secure way to eliminate the long-term credentials?
Choose one.
Workloads should obtain AWS credentials from IAM roles — for EC2, via an instance profile — instead of long-term access keys stored in files, AMIs, or user data.
An instance profile role gives the application short-lived credentials that AWS rotates automatically, removing the long-term keys entirely. Rotating keys or encrypting the file still leaves durable secrets in an artifact, and user data is even more exposed because it is readable via instance metadata — on this exam, any option that keeps access keys on an instance loses to a role.
- Create an IAM role with the S3 permissions the application needs.
- Attach the role to the EC2 instance as an instance profile.
- Update the application to use the default credential chain instead of the configuration file.
- Verify the application works, then deactivate and delete the IAM user's access keys.
Exam tip: Replace access keys on EC2 with an instance profile role — short-lived credentials beat any scheme for protecting long-term keys.
IAM, AWS Organizations, and Compliance Tools for CloudOps (SOA-C03) — the lesson that teaches this.