How to securely allow authenticated users to download S3 objects from an EC2-hosted application?

A company has an application that is hosted on Amazon EC2 instances. The application stores objects in an Amazon S3 bucket and allows users to download objects from the S3 bucket. A developer turns on S3 Block Public Access for the S3 bucket. After this change, users report errors when they attempt to download objects. The developer needs to implement a solution so that only users who are signed in to the application can access objects in the S3 bucket. Which combination of steps will meet these requirements in the MOST secure way? (Choose two.)

  1. Create an EC2 instance profile and role with an appropriate policy. Associate the role with the EC2 instances. Source Reference Answer
  2. Create an IAM user with an appropriate policy. Store the access key ID and secret access key on the EC2 instances.
  3. Modify the application to use the S3 GeneratePresignedUrl API call. Source Reference Answer
  4. Modify the application to use the S3 GetObject API call and to return the object handle to the user.
  5. Modify the application to delegate requests to the S3 bucket.

Community Votes

AC
100%

100% of anonymous learners picked answer AC. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question really tests secure credential management on EC2 and secure, temporary delegation of S3 access to end users, with the common trap being proxying S3 traffic through the application or using long-lived IAM user keys.

This question tests the most secure way to grant authenticated application users access to private S3 objects hosted behind an EC2 application, using IAM roles for EC2 and S3 pre-signed URLs. Community consensus strongly favors combining an EC2 instance profile with GeneratePresignedUrl.

Many candidates choose Option E (delegate requests to S3) because it sounds plausible, but proxying S3 traffic through the EC2 app adds load, complexity, and security risk compared to pre-signed URLs that let users fetch directly from S3.

Community Discussion (7 comments)

SerialiDr 👍 6 Selected: AC
A. Creating an EC2 instance profile and role with an appropriate policy and associating the role with the EC2 instances follows the principle of least privilege. The EC2 instances will have temporary security credentials provided by the role, and the permissions granted to the role can be tightly controlled using IAM policies. This approach eliminates the need to manage and store long-term access keys on the EC2 instances, which can be a security risk. C. Using the S3 GeneratePresignedUrl API call allows the application to generate time-limited URLs that provide temporary access to objects in the S3 bucket. These pre-signed URLs can be generated for authenticated users, ensuring that only authorized users can access the objects. This approach ensures that the objects in the S3 bucket remain private and are not publicly accessible.
wh1t4k3r 👍 2
A is correct. No doubt about it. My problem with C is this: ok, ive generated the presigned URL... now what? You need to update the app to USE de generated url, and there is no mention of that. Im going with E.
Saurabh04 👍 1 Selected: CE
Option C: Modify the application to use the S3 GeneratePresignedUrl API call: Generate a pre-signed URL for each object in the S3 bucket. Provide the pre-signed URL to authenticated users. Users can use the pre-signed URL to download objects directly from S3 without exposing the bucket publicly. Option E: Modify the application to delegate requests to the S3 bucket: Ensure that the application handles authentication and authorization. When a user requests an object, the application verifies their credentials and then retrieves the object from S3. This approach allows fine-grained control over access.
65703c1 👍 2 Selected: AC
AC is the correct answer.
KarBiswa 👍 3 Selected: AC
Presigned Url and appropriate policy
ANDRES715 👍 1 Selected: BC
Cree un usuario de IAM con una política adecuada (opción B): El desarrollador debe crear un usuario de IAM en AWS con una política que permita el acceso a los objetos del depósito S3 solo a los usuarios autenticados en la aplicación. Esta política debe tener permisos adecuados para acceder y descargar objetos del depósito S3. Modifique la aplicación para utilizar la llamada API S3 GeneratePresignedUrl (opción C): El desarrollador debe modificar la aplicación para utilizar la llamada API S3 GeneratePresignedUrl. Esta llamada generará una URL prefirmada que contiene una firma de seguridad y un tiempo de expiración. Solo los usuarios autenticados que tengan acceso a esta URL prefirmada podrán descargar los objetos del depósito S3.
CrescentShared 👍 2 Selected: AC
Option E: Modifying the application to delegate requests to the S3 bucket is less secure than using pre-signed URLs. If the application acts as a proxy for S3 requests, it would need to handle the data transfer from S3 to the user, which can increase the load on the application and potentially expose the application to additional security risks.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the suggested answer (A and C) is correct

The scenario requires two things:

1. Secure credentials on the EC2 instances so the application can call S3 APIs. 2. A secure way to let signed-in users download private S3 objects without making the bucket public.

Option A — Create an EC2 instance profile and role with an appropriate policy, and associate it with the EC2 instances — is the AWS best practice for granting permissions to applications running on EC2. The instance receives temporary security credentials from the role via the Instance Metadata Service (IMDS). This eliminates long-lived credentials on disk and follows the principle of least privilege.

Option C — Modify the application to use the S3 GeneratePresignedUrl API call — allows the application to hand out time-limited, signed URLs to authenticated users. Users then download the object directly from S3, which is both scalable and secure. The bucket can remain fully private with S3 Block Public Access enabled.

Why the other options are wrong

  • Option B (IAM user with access keys stored on EC2) violates AWS security best practices. Long-lived credentials on disk are a major risk and are explicitly discouraged in favor of IAM roles for EC2.
  • Option D (return the object handle to the user) is not a valid S3 pattern and does not provide a secure download mechanism.
  • Option E (delegate requests to the S3 bucket) effectively makes the EC2 instance a proxy. As community member CrescentShared points out, this increases load on the application, adds latency, and introduces additional attack surface. Pre-signed URLs are the more secure and scalable approach.

Community consensus

The vast majority of candidates (87 votes for AC) agree that A + C is the correct combination. A few candidates debated E, but the consensus is clear: pre-signed URLs + IAM roles for EC2 is the AWS-recommended, most secure pattern.

Official Reference

Exam Strategy

When a question asks for the 'MOST secure' way to grant access from an EC2-hosted app, always prefer IAM roles for EC2 over IAM users with access keys, and prefer pre-signed URLs over proxying traffic through your application.

Related Analysis

Practice All DVA-C02 Questions

Access 100 questions with complete answers and detailed explanations.

View Full DVA-C02 Practice Test →

← Back to DVA-C02 Study Guide