How to securely allow authenticated users to download S3 objects from an EC2-hosted application?
A company has an application that is hosted on Amazon EC2 instances. The application stores objects in an Amazon S3 bucket and allows users to download objects from the S3 bucket. A developer turns on S3 Block Public Access for the S3 bucket. After this change, users report errors when they attempt to download objects. The developer needs to implement a solution so that only users who are signed in to the application can access objects in the S3 bucket. Which combination of steps will meet these requirements in the MOST secure way? (Choose two.)
Community Votes
100% of anonymous learners picked answer AC. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question really tests secure credential management on EC2 and secure, temporary delegation of S3 access to end users, with the common trap being proxying S3 traffic through the application or using long-lived IAM user keys.
This question tests the most secure way to grant authenticated application users access to private S3 objects hosted behind an EC2 application, using IAM roles for EC2 and S3 pre-signed URLs. Community consensus strongly favors combining an EC2 instance profile with GeneratePresignedUrl.
Many candidates choose Option E (delegate requests to S3) because it sounds plausible, but proxying S3 traffic through the EC2 app adds load, complexity, and security risk compared to pre-signed URLs that let users fetch directly from S3.
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the suggested answer (A and C) is correct
The scenario requires two things:
1. Secure credentials on the EC2 instances so the application can call S3 APIs. 2. A secure way to let signed-in users download private S3 objects without making the bucket public.
Option A — Create an EC2 instance profile and role with an appropriate policy, and associate it with the EC2 instances — is the AWS best practice for granting permissions to applications running on EC2. The instance receives temporary security credentials from the role via the Instance Metadata Service (IMDS). This eliminates long-lived credentials on disk and follows the principle of least privilege.
Option C — Modify the application to use the S3 GeneratePresignedUrl API call — allows the application to hand out time-limited, signed URLs to authenticated users. Users then download the object directly from S3, which is both scalable and secure. The bucket can remain fully private with S3 Block Public Access enabled.
Why the other options are wrong
- Option B (IAM user with access keys stored on EC2) violates AWS security best practices. Long-lived credentials on disk are a major risk and are explicitly discouraged in favor of IAM roles for EC2.
- Option D (return the object handle to the user) is not a valid S3 pattern and does not provide a secure download mechanism.
- Option E (delegate requests to the S3 bucket) effectively makes the EC2 instance a proxy. As community member CrescentShared points out, this increases load on the application, adds latency, and introduces additional attack surface. Pre-signed URLs are the more secure and scalable approach.
Community consensus
The vast majority of candidates (87 votes for AC) agree that A + C is the correct combination. A few candidates debated E, but the consensus is clear: pre-signed URLs + IAM roles for EC2 is the AWS-recommended, most secure pattern.
Official Reference
Exam Strategy
When a question asks for the 'MOST secure' way to grant access from an EC2-hosted app, always prefer IAM roles for EC2 over IAM users with access keys, and prefer pre-signed URLs over proxying traffic through your application.
Related Analysis
Practice All DVA-C02 Questions
Access 100 questions with complete answers and detailed explanations.
View Full DVA-C02 Practice Test →