SAA-C03 Design Secure Architectures • Set 10
SAA-C03 Design Secure Architectures Practice Test 10 — 15 questions with explanations. Free, no signup.
A platform team manages a multi-tenant SaaS application on Amazon EC2. Each tenant has a dedicated IAM role that the EC2 instances assume via instance profiles. The security team must ensure that a compromised tenant's instance cannot use its role credentials to read or write objects in any other tenant's S3 bucket, even if the role's identity-based policy contains a wildcard Resource. Which combination of controls should the team implement to meet this requirement?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.