An application on an Amazon EC2 instance needs to call other AWS services securely. Which AWS feature should be used to grant that secure access?
Choose an answer
Tap an option to check your answer.
Correct answer: IAM roles.
Why this is the answer
IAM roles are the correct choice because they provide a secure way for AWS services (like an EC2 instance) to obtain temporary credentials to access other AWS services. Instead of embedding long-term credentials directly into the application, the EC2 instance assumes a role, which grants it specific permissions for a defined period. This significantly enhances security by eliminating the need to store static credentials on the instance. Security groups control inbound and outbound network traffic to instances, not access to other AWS services. AWS Firewall Manager helps manage firewall rules across multiple accounts and applications, which is a different security concern. IAM user SSH keys are used for secure shell access to EC2 instances by human users, not for programmatic access by applications to other AWS services.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed