20+ practice questions focused on Design Secure Architectures — one of the most tested topics on the AWS Certified Solutions Architect - Associate exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Design Secure Architectures PracticeRefer to the exhibit. An IAM user has the following policy attached. The user attempts to download a file named 'config.json' located in the 'secrets' folder of the 'app-logs' S3 bucket. What will be the result of this action?
Explanation: The prompt references an exhibit with an IAM user policy, but no exhibit or policy text is provided in the stem. Therefore, the question cannot be properly validated.
A company is migrating a legacy application that uses a custom encryption library. They want to move to AWS KMS but must ensure that even the AWS account administrator cannot use the keys unless they are explicitly granted access in the key policy. How should the key policy be configured?
Explanation: By default, a KMS key policy includes a statement granting the AWS account root user full access to the key. Removing that statement ensures that even the account administrator cannot use the key unless explicitly granted access in the key policy. This is the only way to restrict root-level access because IAM policies alone cannot override the key policy's root grant.
A financial institution stores highly sensitive customer records in Amazon S3 buckets. The Chief Information Security Officer mandates that all uploaded objects must be encrypted at rest using unique keys, and the key material must be fully managed and rotated automatically by AWS. Which TWO actions fulfill these security requirements? (Choose two.)
Explanation: Option B is correct because SSE-KMS with AWS managed keys (aws/s3) encrypts each object with a unique data key derived from a KMS customer master key, and AWS fully manages and automatically rotates that key material, satisfying both the unique-key and automatic-rotation mandates. Option E is correct because a bucket policy that denies PUT requests lacking the x-amz-server-side-encryption header enforces that every uploaded object is encrypted at rest server-side, preventing unencrypted uploads and complementing the default encryption configuration. Option A is not correct because SSE-S3 uses a single AWS-owned master key with no customer-visible key management or configurable automatic rotation, so it does not meet the 'fully managed and rotated' requirement as specified. Option C is not correct because client-side encryption with locally stored custom keys places key management and rotation burden on the institution, not AWS, and risks key loss. Option D is not correct because versioning and MFA delete address data durability and deletion protection, not encryption at rest with unique, AWS-managed, auto-rotated keys.
Refer to the exhibit. A Solutions Architect implemented an Amazon S3 bucket policy to restrict access to corporate network ranges. However, users connecting from corporate laptops inside the approved CIDR block report that they cannot write objects using AWS Lambda functions configured in the same VPC. What is the cause of this access failure?
Explanation: When a Lambda function is configured inside a VPC, its outbound traffic to S3 does not originate from the function's public IP or the corporate CIDR — it originates from the private IP of the Lambda ENI in the VPC subnet. If the Lambda uses a VPC endpoint (Gateway or Interface) to reach S3, the source IP seen by S3 is the private IP of the ENI or the endpoint, not the corporate CIDR block. Therefore the bucket policy's IpAddress condition (aws:SourceIp) fails to match, and the write is denied.
A company is extending its on-premises data center to AWS and requires a secure, high-bandwidth connection that does not traverse the public internet. The connection must support consistent network performance. Which TWO components are needed to establish this connectivity? (Select TWO)
Explanation: AWS Direct Connect (A) is correct because it provides a dedicated, private physical network connection from the on-premises data center to AWS that bypasses the public internet and delivers consistent, high-bandwidth performance. A Virtual Private Gateway (B) is correct because it is the AWS-side VPN gateway that attaches to the VPC and terminates the private virtual interface (VIF) used by the Direct Connect connection, enabling traffic to reach the VPC. Together, Direct Connect plus a Virtual Private Gateway form the standard architecture for private, high-bandwidth hybrid connectivity. An Internet Gateway (C) is not needed because it routes traffic over the public internet, which the scenario explicitly excludes. A NAT Gateway (D) only provides outbound internet access for private subnets and does not establish hybrid connectivity. AWS Client VPN (E) is a software-based remote-access VPN for individual users over the internet, not a dedicated high-bandwidth data center link.
+15 more Design Secure Architectures questions available
Practice all Design Secure Architectures questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Design Secure Architectures. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Design Secure Architectures questions on the SAA-C03 frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Design Secure Architectures is tested as part of the AWS Certified Solutions Architect - Associate blueprint. Practicing with targeted Design Secure Architectures questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free SAA-C03 practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Design Secure Architectures is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Design Secure Architectures practice session with instant scoring and detailed explanations.
Start Design Secure Architectures Practice →