An application running on multiple Amazon EC2 instances publishes messages using Amazon SNS. Which AWS feature should be used to grant the application the permissions it needs to call AWS services securely?
Choose an answer
Tap an option to check your answer.
Correct answer: IAM roles.
Why this is the answer
IAM roles are the correct choice because they provide a secure way to grant permissions to AWS services and applications running on EC2 instances without embedding credentials directly into the code or configuration. An IAM role can be attached to an EC2 instance, allowing applications on that instance to assume the role and inherit its permissions to interact with other AWS services like Amazon SNS. AWS Certificate Manager (ACM) is incorrect because it is used for provisioning, managing, and deploying SSL/TLS certificates, not for granting service permissions. AWS Security Hub is incorrect as it provides a comprehensive view of your security alerts and security posture across your AWS accounts, rather than managing access. Amazon GuardDuty is incorrect because it is a threat detection service that monitors for malicious activity and unauthorized behavior, not for defining permissions.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed