SAA-C03 Design Secure Architectures • Set 19
SAA-C03 Design Secure Architectures Practice Test 19 — 15 questions with explanations. Free, no signup.
A containerized service needs to read exactly one secret value from AWS Secrets Manager. The secret’s ARN is already known, and the secret is encrypted with the AWS-managed KMS key for Secrets Manager, so no separate KMS permissions are needed for this question. The service does not need to list secrets, create secrets, rotate them, or write updates. What is the most least-privilege IAM permission statement to grant the service role?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.