AWS CLF-C02 Practice Question

An application running on EC2 needs to access an S3 bucket without long-term access keys stored in code. Which IAM feature should be used

Domain: Security & Compliance Question 23 of 60 Free practice

Question

An application running on EC2 needs to access an S3 bucket without long-term access keys stored in code. Which IAM feature should be used?

AAn IAM role โœ“
BAn IAM user with a password
CAn access key pair
DAn MFA token
Correct Answer: A

An IAM role

Why this is the right answer

Explanation: An IAM role provides temporary credentials that EC2 instances can assume automatically, avoiding long-lived keys in code.
๐Ÿ“Œ Exam tip: In Security questions, read the "who does what" clues carefully. If the scenario mentions your company managing something, the answer points to the CUSTOMER side of the shared responsibility model; if AWS handles it transparently, it is AWS's responsibility.

Every AWS Cloud Practitioner question on this site comes from the four official CLF-C02 exam domains. Practice the full domain set in our free timed mock exam and review every topic in the CLF-C02 study guide.

Last updated 2026-08-15 ยท Reviewed by the BestHelpTool certification team ยท Official exam details: AWS Certified Cloud Practitioner

Try this question in the interactive practice test

Start free in seconds โ€” no signup, no credit card. Practice questions, timed mock exams with the official 70% pass threshold, and flashcards.