nerdexam
Amazon

SCS-C03 · Question #24

An application is running on an Amazon EC2 instance that has an IAM role attached. The IAM role provides access to an AWS Key Management Service (AWS KMS) customer managed key and an Amazon S3 bucket.

Sign in or unlock SCS-C03 to reveal the answer and full explanation for question #24. The question stem and answer options stay visible for context.

Submitted by certguy· Mar 6, 2026Identity and Access Management (IAM)

Question

An application is running on an Amazon EC2 instance that has an IAM role attached. The IAM role provides access to an AWS Key Management Service (AWS KMS) customer managed key and an Amazon S3 bucket. The key is used to access 2 TB of sensitive data that is stored in the S3 bucket. A security engineer discovers a potential vulnerability on the EC2 instance that could result in the compromise of the sensitive data. Due to other critical operations, the security engineer cannot immediately shut down the EC2 instance for vulnerability patching. What is the FASTEST way to prevent the sensitive data from being exposed?

Options

  • ADownload the data from the existing S3 bucket to a new EC2 instance. Then delete the data from
  • BBlock access to the public range of S3 endpoint IP addresses by using a host-based firewall.
  • CRevoke the IAM role's active session permissions. Update the S3 bucket policy to deny access to
  • DDisable the current key. Create a new KMS key that the IAM role does not have access to, and

Unlock SCS-C03 to see the answer

You've previewed enough free SCS-C03 questions. Unlock SCS-C03 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#IAM role session revocation#KMS key policy#S3 bucket policy#least privilege
Full SCS-C03 Practice