Courseiva

CCNA Design Secure Architectures Questions

51 questions · Design Secure Architectures topic · All types, answers revealed

1
MCQmedium

A developer needs to access an Amazon RDS database from an EC2 instance within a private subnet. The database must only accept traffic from the instance. Which security configuration is most appropriate?

A.Configure the RDS security group to allow inbound traffic from 0.0.0.0/0 on the database port.
B.Configure the RDS security group to allow inbound traffic from the EC2 instance security group ID.
C.Configure the RDS security group to allow inbound traffic from the database's own IP address.
D.Configure the RDS security group to allow inbound traffic from the private IP of the EC2 instance.
AnswerB

Referencing the EC2 security group ID is a best practice for internal VPC communication. It ensures that any instance associated with that security group can connect to the database. This approach is highly dynamic, as it automatically handles instance IP changes and maintains a secure, restricted network path.

Why this answer

Configuring the RDS Security Group to allow inbound traffic on the database port exclusively from the security group ID associated with the EC2 instance follows the principle of least privilege. This stateful configuration ensures that only authorized resources can communicate with the database, significantly reducing the attack surface. By referencing the security group ID instead of an IP address, the architecture remains resilient to dynamic IP changes.

Exam trap

Candidates often suggest using the EC2 instance's private IP address in the RDS security group. This is brittle because IP addresses change when instances are stopped or terminated.

2
MCQmedium

Refer to the exhibit. A security administrator is reviewing a CloudTrail log entry for an 'Access Denied' error. The user 'Alice' is trying to upload a file to an S3 bucket. Alice has an IAM policy that allows 's3:PutObject' on all resources. What is the most likely cause of this error?

A.The S3 bucket has a bucket policy with an explicit Deny for Alice or the action.
B.Alice is not using an encrypted connection (HTTPS) to upload the file.
C.The S3 bucket is located in a different region than the IAM user.
D.Alice's IAM user is missing the 's3:ListBucket' permission.
AnswerA

Even though Alice has an identity-based policy allowing 's3:PutObject', an explicit 'Deny' in a resource-based policy (like a bucket policy) always overrides any 'Allow'. This is a common cause of Access Denied errors when multiple layers of security policies are applied to a resource.

Why this answer

In AWS, access is determined by the intersection of all applicable policies. Even if Alice has an IAM policy allowing the action, an 'Access Denied' error can occur if there is an explicit 'Deny' in a Service Control Policy (SCP), a bucket policy, or if there is a Permissions Boundary restricting her actions.

Exam trap

Candidates often assume that an IAM policy allowing an action is sufficient. They forget that the final authorization decision is the intersection of IAM, SCPs, and resource-based policies like bucket policies.

3
MCQmedium

A company is experiencing unauthorized network traffic in their VPC. They need to inspect traffic patterns between subnets to identify the source of the traffic. Which tool should they use?

A.AWS CloudTrail.
B.AWS Config.
C.VPC Flow Logs.
D.AWS Trusted Advisor.
AnswerC

VPC Flow Logs provide a detailed view of all network traffic flowing through the VPC's network interfaces. This allows security teams to monitor for anomalous patterns, identify unauthorized traffic, and verify that security groups and NACLs are behaving as expected, making it the correct tool for this specific scenario.

Why this answer

VPC Flow Logs capture information about the IP traffic going to and from network interfaces in the VPC. By analyzing these logs, administrators can identify blocked connections, traffic spikes, or unusual destination patterns. This data is essential for security auditing, troubleshooting connectivity issues, and detecting potential malicious activity within the network perimeter, providing the visibility needed to strengthen security policies and Network ACLs.

Exam trap

Candidates often confuse VPC Flow Logs with AWS CloudTrail. CloudTrail logs API calls (management plane), whereas VPC Flow Logs capture network traffic metadata (data plane).

4
MCQmedium

A security team needs to identify and protect sensitive data, such as credit card numbers and passport IDs, that may be stored across hundreds of S3 buckets in multiple AWS accounts. Which service should they use to automate this discovery process?

A.Amazon GuardDuty to monitor S3 data plane events for suspicious activity.
B.Amazon Macie to scan S3 buckets for personally identifiable information (PII).
C.AWS Glue to crawl S3 buckets and catalog the data types found in the files.
D.Amazon Inspector to perform deep packet inspection on data uploaded to S3.
AnswerB

Amazon Macie automatically discovers, classifies, and protects sensitive data at scale. It uses built-in sensitive data identifiers for common PII types and allows for custom identifiers. This makes it the ideal tool for organizations needing to audit their S3 storage for regulatory compliance and data privacy.

Why this answer

Amazon Macie is a fully managed data security and data privacy service that uses machine learning and pattern matching to discover and protect sensitive data in S3. It provides a centralized view of where sensitive data resides and how it is being accessed or moved, which is critical for compliance.

Exam trap

Candidates often select AWS Config or CloudTrail. While these audit configurations and API calls, they do not inspect the actual content of S3 objects for sensitive PII like Macie does.

5
Multi-Selecthard

A company is building a zero-trust architecture for its internal microservices running on Amazon EKS. Which THREE steps should the solutions architect take to ensure secure, least-privilege communication between services? (Select THREE)

Select 3 answers
A.Assign IAM Roles to individual Kubernetes Service Accounts (IRSA).
B.Use AWS App Mesh to enforce Mutual TLS (mTLS) between microservices.
C.Configure Security Groups for Pods to restrict network traffic between services.
D.Place all microservices in a single public subnet to simplify routing.
E.Disable VPC Flow Logs to reduce latency between microservices.
AnswersA, B, C

IRSA allows you to associate an IAM role with a Kubernetes service account. This provides each pod with the minimum necessary AWS permissions to access services like S3 or DynamoDB, rather than giving permissions to the entire worker node, adhering to the principle of least privilege.

Why this answer

Option A is correct because IAM Roles for Service Accounts (IRSA) lets each Kubernetes Service Account assume a distinct IAM role via the EKS OIDC provider, so individual microservices receive only the AWS permissions they need, which is a core least-privilege control in a zero-trust model. Option B is correct because AWS App Mesh enforces mutual TLS (mTLS) between microservices, providing cryptographic identity verification and encrypted service-to-service traffic so that no service is trusted merely by network location. Option C is correct because Security Groups for Pods (using the VPC CNI and ENI trunking) applies EC2 security group rules directly to pod ENIs, enabling fine-grained, least-privilege network segmentation between specific services.

Option D is not appropriate because placing all microservices in a single public subnet exposes them to the internet and removes the network segmentation that zero-trust requires. Option E is not appropriate because disabling VPC Flow Logs reduces visibility and auditability of traffic, which is essential for detecting and investigating lateral movement in a zero-trust architecture.

Exam trap

SAA-C03 often tests the misconception that a single public subnet or disabling logging improves security or performance, when in fact zero-trust requires segmentation, encryption, and monitoring.

6
MCQeasy

An application running on an Amazon EC2 instance needs to securely access data in an Amazon DynamoDB table. What is the most secure way to provide the application with the necessary permissions?

A.Store IAM user credentials in a configuration file on the EC2 instance.
B.Create an IAM role with the required permissions and attach it to the EC2 instance profile.
C.Pass the Access Key and Secret Key as environment variables when starting the application.
D.Embed the credentials directly into the application source code.
AnswerB

Attaching an IAM role to an EC2 instance allows the application to use temporary security credentials provided by the Instance Metadata Service. This eliminates the need to hardcode or store long-term keys, adhering to the principle of least privilege and significantly improving the overall security posture.

Why this answer

Option B is correct because IAM roles attached to an EC2 instance profile provide temporary, automatically rotated credentials to the instance via the Instance Metadata Service (IMDS). The application (or AWS SDK) retrieves these credentials without any hardcoded secrets, and permissions are managed centrally through IAM policies. This eliminates the risk of long-term credential leakage and follows AWS best practices for least privilege.

Exam trap

SAA-C03 often tests the misconception that storing credentials in environment variables or configuration files is acceptable for security, when in fact IAM roles are the only secure, AWS-recommended method for EC2-to-AWS-service authentication.

How to eliminate wrong answers

Option A is wrong because storing IAM user credentials in a configuration file creates long-lived secrets that can be accidentally committed to version control, copied, or stolen, and they require manual rotation. Option C is wrong because environment variables are visible in process listings, crash dumps, and logs, and they still use long-term credentials that must be rotated manually. Option D is wrong because embedding credentials in source code is the least secure method—secrets become part of the codebase, are hard to rotate, and are easily exposed through repositories or build artifacts.

7
MCQmedium

A financial services firm must store transaction logs in Amazon S3 for seven years to meet regulatory requirements. The logs must be protected against any modification or deletion by any user, including the root user, during this period. Which S3 feature should be implemented?

A.Enable S3 Versioning on the bucket to keep a history of all changes made to the logs.
B.Use S3 Glacier Deep Archive as the storage class for the logs with a vault lock policy.
C.Enable S3 Object Lock in compliance mode with a retention period of seven years.
D.Configure AWS Backup to take daily snapshots of the S3 bucket and store them in a secure vault.
AnswerC

S3 Object Lock in compliance mode ensures that an object version cannot be overwritten or deleted by any user, including the root user in the AWS account. This mode is essential for meeting regulatory requirements where data must be preserved and remain unalterable for a specified duration without any exceptions.

Why this answer

S3 Object Lock in compliance mode prevents any user, including the root user, from overwriting or deleting an object version for a specified retention period. This meets the requirement of protecting logs from modification or deletion for seven years. Compliance mode is the strictest mode and cannot be overridden, ensuring regulatory compliance.

Exam trap

SAA-C03 often tests the misconception that versioning or backups provide immutability, but only Object Lock in compliance mode guarantees protection against root user deletion.

How to eliminate wrong answers

Option A is wrong because S3 Versioning alone does not prevent deletion; users can still delete object versions or the bucket, and versioning only keeps a history. Option B is wrong because S3 Glacier Deep Archive with a vault lock policy is for Glacier vaults, not S3 buckets; S3 Glacier Vault Lock is a separate feature for Glacier vaults, not S3 objects. Option D is wrong because AWS Backup snapshots do not prevent deletion of the original S3 objects; they provide a backup copy but do not enforce immutability on the source bucket.

8
MCQmedium

Refer to the exhibit. A security audit identifies that data is being transmitted to an S3 bucket named 'corporate-data' without encryption in transit. Which behavior does this bucket policy enforce to address this concern?

A.It denies any S3 action if the request does not use an encrypted connection (HTTPS).
B.It ensures that all objects stored in the bucket are encrypted using AES-256 server-side encryption.
C.It logs all access attempts to the bucket to identify users who are not using SSL.
D.It automatically redirects all HTTP requests to HTTPS for the specified S3 bucket.
AnswerA

The policy uses a Deny effect combined with a false condition for secure transport, which means any request not using HTTPS is blocked. This is a preventative control that ensures data is encrypted while moving between the client and S3, protecting it from interception by unauthorized parties.

Why this answer

The bucket policy denies any S3 action if the request does not use an encrypted connection (HTTPS). This is enforced by a condition like aws:SecureTransport: false, which blocks HTTP requests. This directly addresses the concern of data in transit being unencrypted.

Exam trap

SAA-C03 often tests the confusion between encryption in transit (HTTPS) and encryption at rest (SSE), tempting candidates to pick an option about server-side encryption when the question specifies 'in transit'.

How to eliminate wrong answers

Option B is wrong because the policy addresses encryption in transit, not server-side encryption at rest (AES-256). Option C is wrong because the policy denies access, not logs it; logging would require a separate logging configuration. Option D is wrong because S3 does not automatically redirect HTTP to HTTPS; the policy simply denies non-HTTPS requests.

9
MCQmedium

An organization needs to issue and manage SSL/TLS certificates for its internal microservices, which are not accessible from the public internet. They want to avoid the overhead of managing their own PKI infrastructure. Which service should they use?

A.AWS Certificate Manager (ACM) to request public certificates for the services.
B.AWS Certificate Manager (ACM) Private Certificate Authority (PCA).
C.AWS CloudHSM to store and manage the private keys for the certificates.
D.Amazon Inspector to audit the certificates used by the microservices.
AnswerB

ACM Private CA allows you to create a private CA hierarchy and issue certificates that are trusted within your organization. It integrates with ACM to automate certificate renewal and management, providing a highly available and secure way to implement TLS for internal applications without the manual effort of managing PKI.

Why this answer

AWS Certificate Manager (ACM) Private Certificate Authority (PCA) is a managed private CA service that helps you easily and securely manage the lifecycle of your private certificates. It eliminates the need for organizations to maintain their own complex and costly internal PKI while still providing the security of private certificates.

Exam trap

Candidates often suggest AWS Certificate Manager (ACM) public certificates. ACM public certificates are for internet-facing resources and cannot be used for internal-only, private microservices.

10
Multi-Selectmedium

A company needs to store database credentials for an application running on Amazon ECS. The credentials must be encrypted and automatically rotated every 30 days without requiring an application restart. Which TWO AWS services should be used together to achieve this? (Select TWO)

Select 2 answers
A.AWS Secrets Manager
B.AWS Lambda
C.AWS Systems Manager Parameter Store
D.AWS Key Management Service (KMS)
E.Amazon DynamoDB
AnswersA, B

AWS Secrets Manager provides built-in support for rotating credentials for Amazon RDS and other databases. It manages the lifecycle of the secret and can trigger a Lambda function to update the database password, making it the primary service for this requirement of automated rotation.

Why this answer

AWS Secrets Manager (A) is correct because it is purpose-built to store and encrypt database credentials and natively supports automatic rotation on a schedule such as every 30 days, so the ECS application can retrieve the latest secret without a restart. AWS Lambda (B) is correct because Secrets Manager rotation is implemented by a Lambda rotation function that performs the four-step rotation (createSecret, setSecret, testSecret, finishSecret) against the database. AWS Systems Manager Parameter Store (C) can hold encrypted parameters but does not provide built-in automatic rotation, so it does not meet the 30-day rotation requirement.

AWS Key Management Service (D) provides the encryption keys used by Secrets Manager but is not itself a secret store or rotation scheduler, so it is not one of the two services to use together. Amazon DynamoDB (E) is a NoSQL database service and has no role in storing or rotating application credentials.

Exam trap

SAA-C03 often tests the confusion between Secrets Manager and Parameter Store; candidates may choose Parameter Store for rotation, but only Secrets Manager has built-in rotation with Lambda.

11
MCQmedium

A web application hosted on EC2 instances needs to access a DynamoDB table. What is the most secure way to provide the application with the necessary permissions?

A.Store IAM access keys in a configuration file on the EC2 instance.
B.Attach an IAM role to the EC2 instance profile.
C.Assign the EC2 instance a public IP address.
D.Use the root user credentials for the application.
AnswerB

IAM roles provide temporary security credentials that are automatically rotated by AWS. By attaching a role to the EC2 instance, the application gains the necessary permissions without the need for static credentials, which is the industry standard for secure service-to-service authentication and authorization within the AWS ecosystem.

Why this answer

Attaching an IAM role to the EC2 instance profile provides temporary, automatically rotated credentials to the application via the instance metadata service, eliminating the need to store long-term keys. This is the AWS-recommended, most secure way to grant EC2-hosted applications access to DynamoDB.

Exam trap

SAA-C03 often tests whether candidates default to IAM roles for AWS service access; the trap is choosing stored access keys or root credentials, which are insecure and operationally burdensome compared to instance profiles.

How to eliminate wrong answers

Option A is wrong because storing IAM access keys in a configuration file creates long-lived credentials that can be leaked, are hard to rotate, and violate least-privilege and credential-hygiene best practices. Option C is wrong because assigning a public IP address has no bearing on IAM permissions and increases the attack surface; it does not grant DynamoDB access. Option D is wrong because using root user credentials is a severe security anti-pattern — root has unrestricted access, cannot be scoped by IAM policies, and should never be used by applications.

12
Multi-Selectmedium

A company is building a mobile application that needs to authenticate users and allow them to upload photos directly to an Amazon S3 bucket. Which TWO Amazon Cognito components should be used to provide a secure and scalable solution?

Select 2 answers
A.Amazon Cognito User Pools to manage user registration and sign-in.
B.Amazon Cognito Identity Pools to provide temporary AWS credentials to users.
C.Amazon Cognito Sync to synchronize user data across multiple devices.
D.IAM Users for each mobile application user to control S3 access.
E.AWS Directory Service to integrate with an on-premises Active Directory.
AnswersA, B

User Pools act as a managed user directory that provides sign-up and sign-in options for app users. They support standard identity providers like Google and Facebook, as well as custom attributes, making them the ideal choice for managing the authentication layer of a modern mobile or web application.

Why this answer

Option A is correct because Amazon Cognito User Pools provide a scalable, managed user directory that handles registration, sign-in, and token issuance (ID, access, and refresh tokens) for the mobile app's authentication layer. Option B is correct because Cognito Identity Pools exchange the User Pool token for temporary, scoped AWS credentials via AWS STS, allowing the app to upload photos directly to S3 without embedding long-term keys. Together they implement the standard authentication-plus-authorization pattern for mobile apps accessing AWS services.

Option C (Cognito Sync) is a legacy data-synchronization service, not an authentication or credential-vending mechanism, and is not needed here. Option D (IAM Users per app user) is an anti-pattern for mobile apps because it requires distributing long-term credentials and does not scale. Option E (AWS Directory Service) is for integrating existing AD/ LDAP directories and does not provide the mobile-native sign-up/sign-in or temporary credential flow required.

Exam trap

The trap is confusing User Pools (authentication) with Identity Pools (authorization/credential vending) — many candidates pick only one, but the question requires both because authentication alone doesn't grant S3 access.

13
MCQmedium

An enterprise requires all data stored in Amazon S3 to be encrypted at rest. The security team must maintain full control over the encryption keys, including the ability to rotate them annually and define access policies for the keys themselves. Which encryption method meets these requirements with the least operational overhead?

A.Use Server-Side Encryption with Amazon S3-Managed Keys (SSE-S3) for all buckets.
B.Implement client-side encryption using a third-party library before uploading objects.
C.Use Server-Side Encryption with AWS KMS Customer Managed Keys (SSE-KMS).
D.Enable Server-Side Encryption with Customer-Provided Keys (SSE-C) for all uploads.
AnswerC

Using SSE-KMS with a Customer Managed Key (CMK) allows the security team to define specific key policies and manage rotation schedules independently. This solution ensures that the security team retains ownership of the cryptographic material while providing the necessary encryption for objects stored within the S3 bucket.

Why this answer

SSE-KMS with Customer Managed Keys (CMKs) allows the security team to create and manage their own KMS keys, including setting key policies, rotating keys annually, and auditing key usage via CloudTrail. It provides full control over the encryption keys while offloading the encryption/decryption process to S3, minimizing operational overhead.

Exam trap

SAA-C03 often tests the confusion between SSE-S3, SSE-KMS, and SSE-C, particularly regarding who manages the keys and the level of control provided.

How to eliminate wrong answers

Option A is wrong because SSE-S3 uses S3-managed keys, giving the customer no control over key rotation or access policies. Option B is wrong because client-side encryption requires the team to manage the encryption process, key storage, and rotation, increasing operational overhead. Option D is wrong because SSE-C requires the customer to provide the encryption key with every request, and they are responsible for key management, which is operationally heavy and does not provide the ability to define key access policies within AWS.

14
MCQmedium

A company is hosting a sensitive web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The compliance team requires that all data at rest must be encrypted using keys that are rotated annually, and all access to these keys must be logged for auditing purposes. Which solution meets these requirements with the least administrative effort?

A.Use AWS CloudHSM to manage encryption keys and manually rotate them every year.
B.Encrypt the EC2 EBS volumes using AWS KMS with automatic key rotation enabled.
C.Implement a third-party encryption tool on the EC2 instances and store keys in an S3 bucket.
D.Use Amazon S3 SSE-S3 to encrypt the EBS volumes and monitor access via VPC Flow Logs.
AnswerB

AWS KMS allows for the creation of customer managed keys that support automatic annual rotation. Once enabled, AWS handles the rotation of the backing key material without requiring changes to the application or EBS configuration. This integrates natively with CloudTrail for auditing, making it the most efficient solution available.

Why this answer

AWS KMS with automatic key rotation enabled on the EBS encryption key satisfies annual rotation, and KMS logs every key operation to CloudTrail for auditing. EBS encryption at rest is configured at the volume level using a KMS CMK, and enabling rotation is a single checkbox or API call — the least administrative effort. CloudHSM and third-party tools require manual rotation and more operational overhead.

Exam trap

SAA-C03 often tests the confusion between S3 encryption (SSE-S3, SSE-KMS) and EBS encryption — candidates who pick SSE-S3 for EBS volumes miss that SSE-S3 is an S3-only feature and EBS uses KMS directly.

How to eliminate wrong answers

Option A is wrong because CloudHSM requires the customer to manage the HSM cluster, key lifecycle, and manual annual rotation, which is significantly more administrative effort than KMS automatic rotation. Option C is wrong because a third-party encryption tool on EC2 instances plus keys stored in S3 is an unmanaged, error-prone design that does not integrate with CloudTrail for key access auditing and requires manual rotation. Option D is wrong because SSE-S3 encrypts S3 objects, not EBS volumes, and VPC Flow Logs capture network metadata, not key access events — the option conflates storage and network services.

15
Multi-Selecthard

A security auditor requires that all EC2 instances must be running with specific software versions and that any instance not compliant with these versions must be automatically terminated. Which THREE services should be used to achieve this? (Select THREE.)

Select 3 answers
A.AWS Systems Manager Inventory.
B.AWS Config.
C.AWS Lambda.
D.AWS Trusted Advisor.
E.AWS CloudFront.
AnswersA, B, C

Systems Manager Inventory collects metadata about software, applications, and configurations installed on EC2 instances. This provides the visibility needed to identify which instances are running the non-compliant software versions, which is the foundational step for both reporting and triggering the remediation actions required by the security audit.

Why this answer

Combining AWS Systems Manager for inventory and automation, AWS Config for continuous compliance monitoring, and Lambda for remediation provides a fully automated governance framework. This approach ensures that the environment is continuously scanned for drift, and non-compliant resources are immediately addressed without human intervention. This setup is crucial for meeting strict regulatory requirements where automated enforcement of security and operational standards is mandatory across a large-scale AWS environment.

Exam trap

Candidates often overlook AWS Config for compliance monitoring. They may select only Systems Manager, but Systems Manager detects the state, while Config is required to trigger the remediation workflow.

16
MCQhard

A large enterprise uses AWS Organizations to manage multiple accounts. The Chief Information Security Officer (CISO) wants to ensure that no account within the organization can create any resources in regions other than 'us-east-1' and 'us-west-2'. What is the most efficient way to enforce this across the entire organization?

A.Create an IAM Group in the management account with a region-restrictive policy and add all users to it.
B.Apply a Service Control Policy (SCP) to the organization root that denies all actions if the region is not 'us-east-1' or 'us-west-2'.
C.Use AWS Config rules in each account to monitor resource creation and delete any resource found in unauthorized regions.
D.Configure a VPC Endpoint for all services and restrict access to specific regions using VPC Endpoint policies.
AnswerB

SCPs provide central control over the maximum permissions available for all accounts in your organization. By applying the policy at the root, the restriction is inherited by all member accounts, including the root user of those accounts, ensuring consistent compliance with the CISO's regional requirements.

Why this answer

SCPs are the only AWS Organizations mechanism that centrally enforce permission guardrails across every account in the OU/root, and they apply to all principals including the root user. A deny statement conditioned on aws:RequestedRegion outside us-east-1/us-west-2 blocks resource creation in unauthorized regions before the API call succeeds. Attaching it at the organization root propagates the restriction to every member account with a single policy, which is the most efficient approach.

Exam trap

SAA-C03 often tests the misconception that IAM policies or Config rules can enforce organization-wide region restrictions, when only SCPs provide preventive, cross-account guardrails.

How to eliminate wrong answers

Option A is wrong because an IAM Group in the management account only affects IAM users in that one account — it has no effect on member accounts, federated identities, or root users, and IAM policies cannot restrict service-level region usage across an organization. Option C is wrong because AWS Config rules are detective, not preventive — they evaluate after the fact and remediation (deleting resources) is reactive, slow, and leaves a window where unauthorized resources exist. Option D is wrong because VPC endpoints only govern traffic to AWS services over private connectivity; they do not prevent resource creation in other regions and cannot be used as a global region guardrail.

17
MCQmedium

Refer to the exhibit. This bucket policy grants access to a specific account. A user in that account still cannot access the object. What is the most likely reason?

A.The bucket policy needs to use 'Effect': 'Deny'.
B.The user in the target account lacks IAM permissions.
C.The bucket policy must include 'Principal': '*'.
D.The resource ARN is incorrectly formatted.
AnswerB

In cross-account access, both the bucket policy and the user's local IAM policy must explicitly permit the action. The bucket policy allows access from the account, but the individual user identity still requires an IAM policy that authorizes the s3:GetObject action to complete the authorization request successfully.

Why this answer

The bucket policy grants cross-account access to the account, but for a user in that account to actually access the S3 object, the user must also have IAM permissions that allow the action (e.g., s3:GetObject). AWS evaluates both the bucket policy and the user's IAM policy; access is granted only if both allow it (unless an explicit deny exists). Since the bucket policy is correct, the missing piece is the user's IAM policy.

Exam trap

SAA-C03 often tests the misconception that a bucket policy alone is sufficient for cross-account access, ignoring the need for IAM permissions in the user's account.

How to eliminate wrong answers

Option A is wrong because using 'Effect': 'Deny' would explicitly deny access, which is the opposite of what is needed; the policy already grants access. Option C is wrong because 'Principal': '*' would grant access to everyone, which is broader than intended and not required for cross-account access; the policy already specifies the correct account principal. Option D is wrong because if the resource ARN were incorrectly formatted, the policy would likely be invalid or not apply, but the scenario states the policy grants access to the account, implying the ARN is correct.

18
MCQmedium

Refer to the exhibit. An administrator has applied the provided bucket policy to 'my-secure-bucket'. What is the effect of this policy on access to the bucket?

A.It allows all users to retrieve objects from the bucket if they are using any IP address.
B.It denies access to anyone from the 192.0.2.0/24 range and allows everyone else.
C.It restricts GetObject access to only those requests originating from the 192.0.2.0/24 CIDR block.
D.It grants full administrative access to the bucket for the 192.0.2.0/24 IP range.
AnswerC

The 'Condition' block acts as a filter on the 'Allow' statement. By using the 'aws:SourceIp' key, the policy ensures that the 's3:GetObject' action is granted only when the request comes from the specified network, effectively implementing a security perimeter around the S3 bucket's data.

Why this answer

The bucket policy uses a Condition with an IpAddress condition key restricting access to the 192.0.2.0/24 CIDR block, and the Action is s3:GetObject. Therefore only requests originating from that IP range are allowed to retrieve objects; all other requests are denied by default because S3 policies are deny-by-default.

Exam trap

SAA-C03 often tests the misconception that an Allow statement with an IP condition denies that IP range, when in fact it permits only that range and implicitly denies everything else.

How to eliminate wrong answers

Option A is wrong because the policy explicitly conditions on the source IP, so not all IP addresses are allowed. Option B is wrong because the policy is an Allow with an IP condition, not a Deny for that range — the range is the only one permitted, not the one blocked. Option D is wrong because the policy only grants s3:GetObject, not full administrative access; administrative actions like s3:PutBucketPolicy or s3:DeleteObject are not included.

19
MCQmedium

A company is migrating a web application to AWS and needs to ensure that all data stored in Amazon S3 is encrypted at rest using keys managed by the company. The company must be able to rotate these keys annually and maintain full control over key access policies. Which solution meets these requirements?

A.Enable S3 Managed Keys (SSE-S3) for all buckets.
B.Use AWS KMS with AWS Managed Keys.
C.Use AWS KMS with Customer Managed Keys.
D.Upload a master key to AWS via the S3 console.
AnswerC

Customer Managed Keys allow the user to define granular key policies and enforce rotation schedules. This provides the level of control required for compliance and security auditing. By managing the key lifecycle, the company fulfills the requirement for ownership and authority over the encryption process for their S3 stored data.

Why this answer

AWS KMS Customer Managed Keys (CMKs) give the company full control over the key policy, allow annual rotation to be enabled, and support auditing via CloudTrail. SSE-S3 uses AWS-owned keys the customer cannot manage or rotate, and AWS Managed Keys have rotation controlled by AWS (every three years) with policies the customer cannot edit. Uploading a raw master key to S3 is not a supported KMS pattern.

Exam trap

SAA-C03 often tests the distinction between SSE-S3, SSE-KMS with AWS Managed Keys, and SSE-KMS with Customer Managed Keys — candidates who pick AWS Managed Keys miss that only CMKs allow customer-controlled rotation and key policies.

How to eliminate wrong answers

Option A is wrong because SSE-S3 uses AES-256 keys fully managed by AWS — the customer has no visibility, no rotation control, and no key policy to manage. Option B is wrong because AWS Managed Keys (aws/s3) rotate automatically every three years and their key policies cannot be customized by the customer, so annual rotation and full access control are not achievable. Option D is wrong because AWS KMS does not accept imported master keys via the S3 console; while KMS does support BYOK via import, that is a KMS API operation, not an S3 console upload, and it still requires a KMS key object.

20
Multi-Selecthard

An enterprise organization is planning a centralized logging architecture across hundreds of AWS accounts using AWS CloudTrail and Amazon S3. Security mandates state that all log files delivered to the centralized S3 bucket must be cryptographically verified to ensure they have not been modified or tampered with after delivery. Which TWO actions must a Solutions Architect implement to achieve this mandate? (Choose two.)

Select 2 answers
A.Enable CloudTrail log file integrity validation on each trail.
B.Configure S3 Object Lock in compliance mode on the centralized logging bucket.
C.Use AWS KMS customer managed keys with automatic key rotation enabled for S3 bucket encryption.
D.Enable Amazon S3 Versioning on the centralized logging bucket to preserve previous object iterations.
E.Verify the digital digests generated by CloudTrail using the AWS CLI or SDK commands.
AnswersA, E

CloudTrail log file integrity validation creates digital signatures of log files using SHA-256 for hashing and SHA-256 with RSA for digital signing. This allows you to verify that log files were not modified, deleted, or forged after delivery.

Why this answer

Option A is correct because CloudTrail log file integrity validation is the feature that produces a digest file for each delivered log file, containing a digital signature (SHA-256 hash signed with a private key) that allows detection of any modification, deletion, or tampering after delivery. Option E is correct because enabling validation alone only generates the digests; the architect must actually validate them by running AWS CLI commands such as 'aws cloudtrail validate-logs' (or SDK equivalents) against the S3 bucket to cryptographically confirm the log files match their digests. Option B is not correct because S3 Object Lock prevents deletion or overwrite of objects going forward but does not cryptographically prove that a delivered log file's contents are unmodified.

Option C is not correct because KMS encryption with key rotation protects data confidentiality and key hygiene, not post-delivery tamper detection. Option D is not correct because S3 Versioning preserves prior object versions but does not itself verify the integrity or authenticity of log file contents.

Exam trap

SAA-C03 often tests the confusion between immutability features (S3 Object Lock, Versioning) and cryptographic integrity verification, causing candidates to select options that prevent tampering but do not verify it.

21
MCQeasy

A company wants to implement a service that continuously monitors for malicious activity and unauthorized behavior across its AWS accounts, such as cryptocurrency mining or unusual API calls. Which AWS service should they use?

A.Amazon Macie
B.AWS Config
C.Amazon GuardDuty
D.AWS CloudTrail
AnswerC

Amazon GuardDuty provides intelligent threat detection by analyzing various data sources including AWS CloudTrail event logs and VPC Flow Logs. It can identify specific threats like EC2 instances communicating with known malicious IP addresses or performing cryptocurrency mining, making it the correct choice for this scenario.

Why this answer

Amazon GuardDuty is a managed threat detection service that continuously monitors AWS accounts for malicious activity and unauthorized behavior using machine learning, anomaly detection, and integrated threat intelligence. It specifically detects findings like cryptocurrency mining, unusual API calls, and compromised instances, which matches the requirement exactly.

Exam trap

The trap is confusing logging and compliance services (CloudTrail, Config) with threat detection — candidates pick CloudTrail because it 'monitors API calls,' but it only records them; GuardDuty is what analyzes them for malicious behavior.

How to eliminate wrong answers

Option A is wrong because Amazon Macie is a data security service that uses machine learning to discover, classify, and protect sensitive data (PII) in S3 — it does not monitor for malicious activity or unauthorized API behavior. Option B is wrong because AWS Config records and evaluates resource configuration changes for compliance, not for threat detection or malicious behavior monitoring. Option D is wrong because AWS CloudTrail logs API activity for auditing and governance, but it does not analyze that activity for threats — it provides the raw data that GuardDuty consumes.

22
Multi-Selectmedium

A solutions architect is designing a storage solution for a financial firm. The firm requires that data stored in Amazon S3 must be protected against accidental deletion and all changes to the data must be versioned. Which TWO features should the architect implement to meet these requirements? (Select TWO)

Select 2 answers
A.Enable S3 Versioning on the bucket.
B.Enable MFA Delete on the bucket.
C.Implement S3 Lifecycle policies to move data to Glacier.
D.Configure a Default Retention Period using S3 Object Lock in Governance mode.
E.Use S3 Block Public Access at the account level.
AnswersA, B

S3 Versioning allows multiple variants of an object to be kept in the same bucket. When an object is deleted, S3 inserts a delete marker instead of permanently removing the data, which allows for easy recovery of the original file and maintains a full history of all changes.

Why this answer

Option A is correct because enabling S3 Versioning on the bucket preserves every prior version of an object, so overwrites and deletes create new versions rather than destroying data, directly satisfying the requirement that all changes to the data be versioned. Option B is correct because MFA Delete adds a second authentication factor requiring the bucket owner's MFA token plus a valid request to permanently delete an object version or to suspend versioning, which protects the versioned data against accidental or malicious deletion. Together, Versioning provides the version history and MFA Delete guards the deletion of those versions, which is exactly the combination the financial firm needs.

Option C is not appropriate because Lifecycle policies only transition or expire objects and do not provide versioning or deletion protection. Option D is not appropriate because S3 Object Lock in Governance mode enforces a retention period (WORM) rather than versioning all changes, and Governance mode can be bypassed by users with special permissions. Option E is not appropriate because Block Public Access only restricts public exposure of the bucket and has nothing to do with versioning or protecting against deletion.

Exam trap

SAA-C03 often tests the distinction between versioning (preserves history) and MFA Delete (requires MFA to permanently delete versions), and candidates frequently confuse Object Lock Governance mode with MFA Delete as deletion protection.

23
Multi-Selecthard

A company is designing a multi-tier application. The web tier is public, and the database tier is private. Which TWO actions should the architect take to ensure the database tier is secure? (Select TWO.)

Select 2 answers
A.Place the database instances in a public subnet with a restrictive Network ACL.
B.Place the database instances in a private subnet.
C.Allow the database security group to receive traffic from the web tier security group.
D.Attach an Internet Gateway to the private subnet route table.
E.Use a Network ACL to allow all traffic from the internet to the database.
AnswersB, C

Private subnets are designed for backend resources that do not require direct internet access. By placing the database here, the architect ensures that the database is not exposed to the public internet, satisfying the fundamental security requirement for protecting backend data tiers from external unauthorized access attempts.

Why this answer

Option B is correct because placing the database instances in a private subnet removes them from direct internet reachability, since private subnets have no route to an Internet Gateway, which is the foundational control for protecting a database tier. Option C is correct because referencing the web tier's security group as the source in the database security group's inbound rule enforces least-privilege, instance-level access so only the web tier can reach the database on the required port (for example, 3306 for MySQL or 5432 for PostgreSQL). Option A is wrong because a public subnet is routable to the internet, so even with a restrictive Network ACL the database would still be exposed at the subnet level.

Option D is wrong because attaching an Internet Gateway to the private subnet's route table would make that subnet public and expose the database to inbound internet traffic. Option E is wrong because allowing all internet traffic to the database via a Network ACL directly violates the requirement to keep the database tier private and secure.

Exam trap

SAA-C03 often tests the misconception that a Network ACL alone can secure a database in a public subnet, but private subnet placement and security group references are essential.

24
Multi-Selectmedium

An architect is designing a secure storage solution for highly sensitive financial data in S3. Which THREE security controls should be implemented? (Select THREE.)

Select 3 answers
A.Enable S3 Block Public Access at the account level.
B.Use AWS KMS with Customer Managed Keys for encryption at rest.
C.Use Bucket Policies to enforce HTTPS/TLS access.
D.Allow all users in the organization to have full access.
E.Store data in a public bucket for easier access.
AnswersA, B, C

Blocking public access acts as a centralized safeguard to prevent accidental exposure of S3 buckets to the public internet. This is a crucial first line of defense, ensuring that no bucket within the account can be made public, regardless of individual bucket policy or IAM configuration errors.

Why this answer

Option A is correct because enabling S3 Block Public Access at the account level applies account-wide guardrails that override bucket policies and ACLs, preventing any bucket or object from being made public—an essential baseline for highly sensitive financial data. Option B is correct because AWS KMS with Customer Managed Keys (CMKs) gives the organization control over the key policy, rotation, and grants, providing encryption at rest with auditable key usage via CloudTrail, which is required for regulated financial data. Option C is correct because bucket policies using the aws:SecureTransport condition (e.g., "aws:SecureTransport": "false" with Deny) enforce HTTPS/TLS for all requests, preventing data in transit from being exposed over plain HTTP.

Option D is incorrect because granting all users in the organization full access violates least privilege and would allow unauthorized or accidental modification or exfiltration of sensitive data. Option E is incorrect because storing data in a public bucket exposes it to the internet and directly contradicts the requirement for a secure storage solution.

Exam trap

SAA-C03 often tests the shared responsibility model and S3 security best practices, and candidates may incorrectly believe that making a bucket public with IP restrictions is secure, or that broad organizational access is acceptable for sensitive data.

25
MCQmedium

A company is using AWS Secrets Manager to manage database credentials. The company needs to automatically rotate these credentials every 30 days. How can this be accomplished?

A.Manually update the secret every 30 days.
B.Use a Lambda function integrated with Secrets Manager.
C.Use AWS Config to trigger a password reset.
D.Use Amazon SNS to send an alert for manual rotation.
AnswerB

Secrets Manager uses a Lambda function to perform the actual credential update on the database. This allows for customized rotation logic, such as updating the password in the database engine and then updating the entry in Secrets Manager, ensuring a seamless and fully automated end-to-end rotation lifecycle.

Why this answer

AWS Secrets Manager supports automatic rotation by invoking a Lambda function that implements the rotation logic (create new secret, update the database, test, and finalize). Configuring the rotation schedule (e.g., every 30 days) on the secret triggers this Lambda automatically, eliminating manual intervention.

Exam trap

The trap is selecting AWS Config or SNS because they sound like automation/management services, but only Secrets Manager's native Lambda integration performs actual credential rotation.

How to eliminate wrong answers

Option A is wrong because manual updates do not provide automatic rotation and are error-prone, violating the requirement for automatic 30-day rotation. Option C is wrong because AWS Config is a configuration compliance service, not a credential rotation mechanism, and cannot reset database passwords. Option D is wrong because SNS only sends notifications; it does not perform rotation, so the credentials would still require manual updates.

26
MCQmedium

An organization wants to protect their web application from common web exploits like SQL injection and cross-site scripting (XSS). Which AWS service should they use?

A.AWS Shield Standard.
B.AWS WAF.
C.Amazon GuardDuty.
D.Network ACLs.
AnswerB

AWS WAF provides the ability to define rules that block specific application-layer exploits. By applying these rules to an ALB or CloudFront distribution, the organization can actively prevent SQL injection and XSS attacks, directly addressing the requirement to protect the application from these common web-based vulnerabilities.

Why this answer

AWS WAF is the managed web application firewall that inspects HTTP/HTTPS requests at Layer 7 and applies rules to block SQL injection, cross-site scripting, and other OWASP Top 10 exploits. It integrates with CloudFront, ALB, API Gateway, and AppSync, and supports managed rule groups plus custom rules. AWS Shield Standard only defends against Layer 3/4 DDoS, not application-layer exploits.

Exam trap

SAA-C03 often tests the confusion between Shield (DDoS, Layers 3/4) and WAF (application-layer exploits, Layer 7) — candidates who see 'protect from attacks' and pick Shield miss that SQLi/XSS are explicitly Layer 7 concerns.

How to eliminate wrong answers

Option A is wrong because AWS Shield Standard provides automatic DDoS protection at Layers 3 and 4 and does not inspect HTTP payloads for SQLi or XSS. Option C is wrong because Amazon GuardDuty is a threat-detection service that analyzes VPC Flow Logs, DNS logs, and CloudTrail to surface suspicious activity — it detects but does not block web exploits. Option D is wrong because Network ACLs are stateless Layer 3/4 subnet-level filters that operate on IP/port/protocol and cannot parse HTTP request bodies or query strings.

27
MCQmedium

A company must share an S3 bucket with a third-party vendor. The vendor has their own AWS account. What is the most secure method to grant the vendor access to the S3 bucket?

A.Share the company's IAM user credentials with the vendor.
B.Create an IAM user for the vendor and share the access keys.
C.Create a cross-account IAM role for the vendor to assume.
D.Make the S3 bucket public and restrict by IP address.
AnswerC

A cross-account role provides a secure, temporary, and audited method for external access. The vendor assumes the role using their own credentials, which AWS then swaps for temporary security tokens. This provides the company with full control over the permissions assigned to the role and the duration of access.

Why this answer

Creating a cross-account IAM role allows the vendor to assume a role in the company's account using their own credentials, granting temporary, scoped access to the S3 bucket without sharing long-term credentials. This follows AWS security best practices for least privilege and credential management. It is the most secure method because no permanent secrets are exchanged.

Exam trap

SAA-C03 often tests the difference between long-term IAM user credentials and temporary role-based access, and candidates may incorrectly choose sharing access keys as a simpler solution without recognizing the security risks.

How to eliminate wrong answers

Option A is wrong because sharing IAM user credentials violates AWS security best practices and gives the vendor full access to that user's permissions, with no auditability or revocation ease. Option B is wrong because creating an IAM user for the vendor and sharing access keys still involves long-term credentials that can be leaked or misused, and it does not follow the principle of least privilege. Option D is wrong because making the bucket public, even with IP restrictions, exposes data to potential unauthorized access and is not considered secure for sensitive data.

28
MCQmedium

Refer to the exhibit. An IAM policy is applied to an IAM user to grant access to an S3 bucket. However, the user is still receiving an 'Access Denied' error when attempting to list the objects in the bucket. What is the cause of this error?

A.The policy is missing the s3:ListBucket permission.
B.The user does not have an IAM role attached.
C.The bucket policy is explicitly denying access.
D.The S3 bucket is encrypted with a KMS key.
AnswerA

The s3:ListBucket action is required to list the contents of an S3 bucket. The current policy only provides read access to the objects themselves, not the bucket's file listing. Adding this action to the policy will resolve the Access Denied error when performing the list command.

Why this answer

The provided policy grants the 's3:GetObject' permission, which allows the user to read specific objects within the bucket, but it does not grant 's3:ListBucket'. The ListBucket permission is required to view the contents of the bucket. Since the user lacks this permission, the operation fails with an Access Denied error despite having access to individual objects.

This is a common permissions oversight in IAM policy management.

Exam trap

Candidates assume that 'GetObject' permission implicitly grants the ability to see the bucket contents. In reality, listing the bucket and accessing an object are two distinct, granular S3 API permissions.

29
MCQeasy

A company is launching a high-profile marketing campaign and expects a significant increase in traffic. They are concerned about potential Distributed Denial of Service (DDoS) attacks targeting their Application Load Balancer. Which AWS service provides advanced protection and includes 24/7 access to the AWS Shield Response Team (SRT)?

A.AWS Shield Standard
B.AWS Shield Advanced
C.AWS WAF
D.AWS Global Accelerator
AnswerB

AWS Shield Advanced offers tailored protection for applications running on EC2, ELB, CloudFront, and Route 53. It provides sophisticated detection, real-time visibility into attacks, and direct access to the AWS Shield Response Team for manual intervention during complex attacks, ensuring maximum availability for critical campaigns.

Why this answer

AWS Shield Advanced provides expanded DDoS protection for web applications. Unlike the free Standard tier, it includes additional mitigation capabilities, 24/7 access to the Shield Response Team, and financial protection against bill spikes caused by DDoS attacks, making it ideal for high-profile applications.

Exam trap

Candidates often assume standard AWS Shield provides 24/7 support. Standard is included for free but lacks the dedicated response team and advanced mitigation features found in the paid Advanced tier.

30
MCQmedium

A company wants to ensure that no developer can create an Amazon S3 bucket in any AWS region except for us-east-1 and us-west-2 across their entire AWS Organization. Which solution provides the most efficient and centralized way to enforce this across all member accounts?

A.Apply an IAM policy to every developer user in each account that denies s3:CreateBucket in restricted regions.
B.Configure an S3 bucket policy on all existing buckets to prevent the creation of new buckets in other regions.
C.Attach a Service Control Policy (SCP) to the organization root that denies s3:CreateBucket if the region is not us-east-1 or us-west-2.
D.Enable AWS Config in all accounts and create a custom rule to delete any bucket created in a restricted region.
AnswerC

Service Control Policies allow the organization's management account to set the maximum available permissions for member accounts. A Deny rule in an SCP acts as a guardrail that overrides any local IAM permissions, ensuring that restricted services or regions remain inaccessible regardless of local configurations within the accounts.

Why this answer

A Service Control Policy (SCP) attached to the organization root applies to all member accounts and can deny s3:CreateBucket when the requested region is not us-east-1 or us-west-2. SCPs are the centralized, efficient way to enforce guardrails across an AWS Organization, affecting all principals without per-account changes.

Exam trap

SAA-C03 often tests the misconception that IAM policies or bucket policies can enforce organization-wide region restrictions, when only SCPs provide centralized preventive control.

How to eliminate wrong answers

Option A is wrong because applying IAM policies to every developer in each account is not centralized, is error-prone, and new accounts or users would not be covered. Option B is wrong because S3 bucket policies apply to existing buckets and cannot prevent the creation of new buckets in other regions. Option D is wrong because AWS Config rules are reactive and only delete non-compliant buckets after creation, not prevent them; it also requires per-account setup.

31
MCQmedium

A company is concerned about unauthorized access and potential data exfiltration within their AWS environment. They need a service that can continuously monitor VPC Flow Logs, AWS CloudTrail management events, and DNS logs to identify suspicious activities using machine learning. Which solution should the architect recommend for centralized threat detection?

A.Enable Amazon GuardDuty and integrate it with AWS Organizations for cross-account visibility.
B.Configure AWS Inspector to perform network reachability assessments on all EC2 instances.
C.Deploy AWS Shield Advanced to protect all public-facing endpoints from DDoS attacks.
D.Use AWS Config to monitor changes in security group rules and VPC configurations.
AnswerA

Amazon GuardDuty continuously monitors for malicious activity and unauthorized behavior using machine learning and threat intelligence. It analyzes data sources like VPC Flow Logs and CloudTrail to identify anomalies. This managed service provides a comprehensive view of the security posture across multiple AWS accounts through integration with AWS Organizations.

Why this answer

Amazon GuardDuty is a threat detection service that continuously monitors VPC Flow Logs, AWS CloudTrail management events, and DNS logs using machine learning and threat intelligence to identify suspicious activities. Integrating it with AWS Organizations enables centralized threat detection across all accounts, matching the requirement for cross-account visibility.

Exam trap

SAA-C03 often tests the confusion between GuardDuty (threat detection) and Inspector (vulnerability assessment) or Config (configuration compliance), causing candidates to select a service that doesn't analyze logs for threats.

How to eliminate wrong answers

Option B is wrong because AWS Inspector performs vulnerability assessments on EC2 instances and container images, not continuous threat detection from logs. Option C is wrong because AWS Shield Advanced provides DDoS protection, not threat detection from VPC Flow Logs, CloudTrail, or DNS logs. Option D is wrong because AWS Config monitors resource configuration changes and compliance, but does not analyze logs with machine learning for threat detection.

32
Multi-Selecthard

An organization is using AWS Control Tower to manage multiple AWS accounts. They need to implement a set of guardrails to ensure that all accounts remain compliant with security best practices. Which THREE components or features are part of a standard AWS Control Tower landing zone implementation?

Select 3 answers
A.Preventive guardrails implemented using Service Control Policies (SCPs).
B.Detective guardrails implemented using AWS Config rules.
C.A centralized logging account and a security tooling account.
D.Amazon Macie enabled by default on all S3 buckets in member accounts.
E.Amazon GuardDuty for automated threat detection across all accounts.
AnswersA, B, C

Control Tower uses preventive guardrails to stop actions that would lead to non-compliance. These are implemented as SCPs that are applied to Organizational Units (OUs). For example, a preventive guardrail might block the ability to disable CloudTrail or change critical security settings across all member accounts.

Why this answer

Option A is correct because AWS Control Tower preventive guardrails are enforced through Service Control Policies (SCPs) attached to OUs, which restrict what actions member accounts can perform. Option B is correct because detective guardrails in Control Tower are implemented as AWS Config rules (often deployed via conformance packs) that detect and flag noncompliant resources. Option C is correct because a standard Control Tower landing zone provisions a dedicated log archive account for centralized logging and an audit (security tooling) account for security and compliance tooling.

Option D is incorrect because Amazon Macie is not enabled by default on all S3 buckets as part of the landing zone; it is an optional data-security service. Option E is incorrect because GuardDuty is not automatically enabled across all accounts by Control Tower itself; it can be integrated via services like AWS Security Hub or delegated administration, but it is not a built-in landing zone component.

Exam trap

SAA-C03 often tests which services are mandatory landing zone components vs optional add-ons, baiting candidates who assume popular services like GuardDuty or Macie are enabled by default.

33
Multi-Selectmedium

A security architect is designing a multi-tier application in a VPC. The requirement is to block all traffic from a specific range of malicious IP addresses (CIDR 192.0.2.0/24) while allowing standard web traffic (HTTPS) from all other sources to the web tier. Which TWO actions should the architect take to implement this? (Select TWO.)

Select 2 answers
A.Create an inbound rule in the Network ACL to deny traffic from 192.0.2.0/24.
B.Add a deny rule to the web tier Security Group for CIDR 192.0.2.0/24.
C.Configure AWS Shield Standard to automatically block the 192.0.2.0/24 subnet.
D.Configure the web tier Security Group to allow inbound traffic on port 443 from 0.0.0.0/0.
E.Update the VPC Route Table to blackhole all traffic destined for 192.0.2.0/24.
AnswersA, D

Network ACLs act as a firewall for associated subnets and are stateless, meaning they require rules for both inbound and outbound traffic. They support explicit deny rules, which allow administrators to block specific malicious CIDR blocks from entering the network at the earliest possible entry point.

Why this answer

Option A is correct because Network ACLs are stateless, subnet-level firewalls that support explicit deny rules, so an inbound deny rule for 192.0.2.0/24 blocks that malicious CIDR before it can reach any resource in the subnet. Option D is correct because Security Groups are stateful, instance-level firewalls that only support allow rules, so permitting inbound TCP port 443 from 0.0.0.0/0 allows standard HTTPS web traffic from all other sources to the web tier. Together these satisfy both requirements: the NACL denies the malicious range while the Security Group allows HTTPS from everywhere else.

Option B is wrong because Security Groups cannot contain deny rules; they are allow-only. Option C is wrong because AWS Shield Standard provides automatic protection against common DDoS attacks and does not let you block a specific CIDR like 192.0.2.0/24. Option E is wrong because route tables control routing, not inbound filtering, and blackholing a destination CIDR would not block inbound traffic from that source to the web tier.

Exam trap

SAA-C03 often tests the difference between Security Groups (allow-only) and NACLs (allow/deny), and candidates may incorrectly try to add a deny rule to a Security Group.

34
MCQmedium

A company wants to improve the security of its Amazon RDS for PostgreSQL database. They want to eliminate the need for storing database passwords in application code and simplify the management of database access for their EC2-based applications. Which solution should they implement?

A.Configure the RDS instance to use IAM Database Authentication and assign a role to the EC2 instances.
B.Use AWS Secrets Manager to store the RDS credentials and retrieve them at runtime.
C.Enable SSL/TLS encryption for all database connections to protect the password in transit.
D.Store the database password in a private S3 bucket and allow the EC2 instances to read the file.
AnswerA

IAM Database Authentication allows applications to connect to RDS using an authentication token generated by IAM. This method leverages the EC2 instance profile to provide the necessary permissions, ensuring that credentials are never stored in the code and are automatically managed and rotated by AWS.

Why this answer

IAM Database Authentication for RDS for PostgreSQL lets EC2 instances (or other AWS principals) authenticate to the database using short-lived authentication tokens generated from their IAM role credentials, so no static database password is ever stored in application code. The EC2 instance assumes an IAM role, and the RDS instance is configured to allow IAM authentication; the application then calls generate-db-auth-token (or the SDK equivalent) to obtain a 15-minute token used as the password. This eliminates password storage and centralizes access management through IAM policies, satisfying both the security and simplification goals.

Exam trap

SAA-C03 often tests the distinction between eliminating static credentials entirely (IAM database authentication) and merely managing them more securely (Secrets Manager); candidates frequently pick Secrets Manager because it sounds like a best practice, but the question specifically asks to eliminate the need for storing passwords in application code, which IAM authentication does more directly.

How to eliminate wrong answers

Option B is wrong because AWS Secrets Manager still requires the application to retrieve and use a stored password, so a secret (albeit managed) is still involved and the application must handle it at runtime; it does not eliminate password storage in the sense of removing static credentials from the authentication flow, and it adds rotation complexity. Option C is wrong because SSL/TLS only encrypts data in transit; it does not remove the need to store a database password in application code or simplify access management. Option D is wrong because storing a password in an S3 bucket is an insecure anti-pattern that still requires the application to fetch and use a static password, and it does not provide IAM-integrated database authentication.

35
MCQmedium

A company's security team identifies that its public-facing web application is being targeted by SQL injection and cross-site scripting (XSS) attacks. The application is running on EC2 instances behind an Application Load Balancer (ALB). Which service should the solutions architect implement to protect the application from these specific web-based attacks?

A.AWS Shield Advanced
B.Amazon GuardDuty
C.AWS WAF
D.Amazon Inspector
AnswerC

AWS WAF allows users to create web ACLs that contain rules to inspect HTTP/HTTPS requests. It includes pre-configured managed rule groups that specifically target SQL injection and XSS patterns, providing a robust defense layer at the application level to mitigate these common security threats effectively.

Why this answer

AWS WAF is purpose-built to inspect HTTP/HTTPS requests at Layer 7 and block application-layer exploits such as SQL injection and cross-site scripting. It integrates natively with ALB, CloudFront, and API Gateway, and provides managed rule groups (e.g., AWSManagedRulesSQLiRuleSet, AWSManagedRulesCommonRuleSet) that detect these exact attack patterns. Because the workload sits behind an ALB, WAF can be attached directly to the load balancer to filter malicious requests before they reach the EC2 instances.

Exam trap

SAA-C03 often tests the confusion between AWS WAF (Layer 7 application attacks like SQLi/XSS) and AWS Shield (Layer 3/4 DDoS), causing candidates to pick Shield Advanced when the question explicitly names web exploits.

How to eliminate wrong answers

Option A is wrong because AWS Shield Advanced only mitigates volumetric DDoS attacks at Layers 3/4 (and some Layer 7 DDoS via automatic WAF rule creation), but it does not natively detect SQL injection or XSS payloads. Option B is wrong because Amazon GuardDuty is a threat-detection service that analyzes VPC Flow Logs, DNS logs, and CloudTrail events to surface findings — it does not block or filter HTTP requests. Option D is wrong because Amazon Inspector is a vulnerability management service that scans EC2 instances and container images for software CVEs and network exposure; it does not inspect live HTTP traffic for injection attacks.

36
MCQeasy

A company wants to ensure that its internal applications can access Amazon S3 without the traffic ever leaving the AWS network or passing through the public internet. What should they implement to achieve this securely?

A.Configure a NAT Gateway in a public subnet to route S3 traffic.
B.Use an AWS Direct Connect connection between the VPC and S3.
C.Create a VPC Gateway Endpoint for Amazon S3 and update the route tables.
D.Set up a VPN connection between the private subnet and the S3 service.
AnswerC

A Gateway Endpoint for S3 is a cost-effective and highly available way to provide private access to S3. It does not require a NAT gateway or public IP addresses. By adding a route to the VPC route table, all traffic to S3 is automatically routed through the private endpoint.

Why this answer

A VPC Gateway Endpoint for Amazon S3 provides a private, logical connection between a VPC and S3 that keeps traffic on the AWS backbone and never traverses the public internet. Updating route tables to direct S3-bound traffic to the gateway endpoint ensures instances in private subnets reach S3 privately.

Exam trap

The trap is choosing NAT Gateway or VPN because they provide connectivity, but the question's key constraint — traffic never leaving the AWS network — rules them out; only a VPC Gateway Endpoint satisfies that requirement for S3.

How to eliminate wrong answers

Option A is wrong because a NAT Gateway routes traffic through the public internet (via an internet gateway), which violates the requirement that traffic never leave the AWS network. Option B is wrong because AWS Direct Connect is a dedicated physical connection from on-premises to AWS, not a mechanism for VPC-to-S3 private access within AWS. Option D is wrong because a VPN connection encrypts traffic but still routes it over the public internet, and it is designed for on-premises-to-VPC connectivity, not VPC-to-S3.

37
MCQmedium

An organization needs to perform continuous security assessments of its Amazon EC2 instances to identify software vulnerabilities and unintended network exposure. Which service should they use to automate these assessments and provide a centralized view of the findings?

A.AWS Trusted Advisor to check for security groups that allow unrestricted access.
B.Amazon Inspector to automatically discover and scan EC2 instances for vulnerabilities.
C.AWS CloudTrail to monitor and log all API calls made to the EC2 instances.
D.VPC Flow Logs to analyze traffic patterns and identify potential security threats.
AnswerB

Amazon Inspector provides automated, continuous vulnerability scanning for EC2 instances and container images. It uses a unified findings format and integrates with AWS Security Hub, making it the standard choice for organizations looking to automate their vulnerability management and maintain a high level of security compliance.

Why this answer

Amazon Inspector is an automated vulnerability management service that continually scans AWS workloads for software vulnerabilities and unintended network exposure. It is particularly effective for EC2 instances as it can scan both the operating system and the installed applications, providing detailed findings and remediation advice to improve the security posture.

Exam trap

Candidates often choose AWS Config or Trusted Advisor. While helpful, these do not perform deep vulnerability scanning of the operating system and installed software packages like Inspector does.

38
MCQmedium

A company is developing a mobile application that allows users to sign in using their social media accounts (e.g., Google or Facebook). After signing in, the application needs to obtain temporary AWS credentials to upload photos directly to an Amazon S3 bucket. Which service should the architect use?

A.AWS IAM User with static access keys
B.Amazon Cognito
C.AWS Directory Service
D.AWS Security Token Service (STS) with a manual web identity federation implementation
AnswerB

Amazon Cognito Identity Pools enable you to grant your users temporary, limited-privilege access to AWS resources. By federating with social providers, Cognito manages the exchange of identity tokens for AWS STS credentials, providing a secure and scalable way for mobile users to interact with AWS services directly.

Why this answer

Amazon Cognito provides identity pools that directly support social identity providers (Google, Facebook, Amazon, Apple) and exchange the resulting tokens for temporary, scoped AWS credentials via STS. This is the managed, recommended way to implement web identity federation for mobile apps without building the token-exchange flow yourself. Cognito user pools handle authentication, and identity pools handle AWS credential vending.

Exam trap

SAA-C03 often tests Cognito vs manual STS web identity federation, baiting candidates who know STS is the underlying mechanism but miss that Cognito is the managed, recommended service for social login.

How to eliminate wrong answers

Option A is wrong because embedding static IAM user access keys in a mobile app is a severe security anti-pattern — keys can be extracted from the app binary and cannot be safely rotated per user. Option C is wrong because AWS Directory Service is for managed Microsoft AD or Simple AD integration with enterprise directories, not social media login federation. Option D is wrong because while STS AssumeRoleWithWebIdentity is the underlying mechanism, implementing web identity federation manually means building and maintaining the token validation, provider trust, and credential refresh logic that Cognito already provides — it is not the recommended service-level answer.

39
MCQmedium

A company is hosting a web application on EC2 instances behind an Application Load Balancer. The security team requires that all data in transit between the client and the ALB be encrypted using TLS. Which service should the architect use to manage the SSL/TLS certificates for the ALB?

A.AWS Secrets Manager
B.AWS Certificate Manager (ACM)
C.AWS Key Management Service (KMS)
D.IAM Server Certificate Upload
AnswerB

ACM provides a managed service to generate or import SSL/TLS certificates and associate them directly with an ALB. It handles the complexities of certificate lifecycle management, including automated renewals, ensuring that the web application maintains continuous, encrypted communication with clients without manual intervention or certificate expiration risks.

Why this answer

AWS Certificate Manager (ACM) is the managed service designed to provision, manage, and deploy public and private SSL/TLS certificates for use with AWS services like Application Load Balancers, CloudFront, and API Gateway. ACM handles certificate renewal automatically and integrates natively with ALB listeners, making it the correct choice for managing TLS certificates for the ALB.

Exam trap

The trap is confusing certificate management (ACM) with key management (KMS) or secret storage (Secrets Manager), or falling back to the legacy IAM certificate upload method that lacks automatic renewal.

How to eliminate wrong answers

Option A is wrong because AWS Secrets Manager is for storing and rotating secrets such as database credentials and API keys, not for issuing or managing TLS certificates that integrate with ALB listeners. Option C is wrong because AWS KMS is a key management service for encryption keys used to encrypt data at rest, not for provisioning or deploying SSL/TLS certificates to load balancers. Option D is wrong because IAM Server Certificate Upload is a legacy method for uploading third-party certificates to IAM for use with ELB Classic and CloudFront; it does not provide managed renewal and is not the recommended approach for ALB, which uses ACM.

40
MCQhard

Refer to the exhibit. A company has applied the following bucket policy to an S3 bucket named 'finance-reports'. A user is attempting to download a file from this bucket from the IP address 203.0.113.15 using an authenticated session without MFA. What will be the result of this request?

A.The request will be allowed because the IP address is within the allowed range.
B.The request will be denied because both conditions must be true for the policy to grant access.
C.The request will be allowed because the 'Bool' condition is only evaluated if MFA is configured.
D.The request will be denied because S3 bucket policies require an explicit 'Deny' statement to block traffic.
AnswerB

In AWS policy evaluation, multiple conditions within a single statement are evaluated using a logical AND. The user has the correct source IP, but because they did not authenticate with Multi-Factor Authentication, the second condition fails, and the permission is not granted to the user.

Why this answer

S3 bucket policy conditions are evaluated with AND logic by default — all conditions in a single Condition block must be true for the statement to apply. Since the request comes from an allowed IP but lacks MFA authentication, the Bool condition (aws:MultiFactorAuthPresent = true) fails, so the policy does not grant access and the request is denied.

Exam trap

SAA-C03 often tests whether candidates understand that multiple conditions in a single S3 policy statement are ANDed, not ORed — candidates incorrectly assume satisfying one condition is enough.

How to eliminate wrong answers

Option A is wrong because satisfying only the IP condition is insufficient — the MFA Bool condition must also be true, and AND logic applies across all conditions in the statement. Option C is wrong because the 'aws:MultiFactorAuthPresent' condition key is evaluated regardless of whether MFA is configured; if the key is absent or false, the condition evaluates to false and access is denied. Option D is wrong because S3 bucket policies use implicit deny — if no statement explicitly allows the action, access is denied; an explicit Deny is not required to block the request.

41
MCQmedium

A company is hosting a multi-tier web application on AWS using Amazon EC2 instances in a private subnet behind an Application Load Balancer (ALB). The security team requires that all incoming web traffic is encrypted in transit from the client to the ALB and from the ALB to the backend EC2 instances. Which combination of configurations meets these requirements?

A.Configure an HTTP listener on the ALB and configure the backend instances to accept HTTP traffic on port 80.
B.Configure an HTTPS listener on the ALB and route traffic to the backend instances using HTTP on port 80.
C.Configure an HTTPS listener on the ALB using an ACM certificate and configure the backend instances to accept HTTPS traffic.
D.Configure a TCP listener on the ALB and install self-signed certificates directly on the target EC2 instances.
AnswerC

Deploying an HTTPS listener on the ALB terminates client TLS securely using certificates managed by AWS Certificate Manager, while forwarding traffic over HTTPS to backend instances satisfies the explicit requirement for comprehensive end-to-end encryption across all application tiers.

Why this answer

To encrypt traffic from client to ALB, an HTTPS listener with an ACM certificate is required. To encrypt traffic from ALB to backend EC2 instances, the backend must accept HTTPS (TLS) traffic, which means the ALB target group protocol must be HTTPS and the instances must have certificates installed and be listening on the HTTPS port. Option C is the only one that satisfies both requirements.

Exam trap

SAA-C03 often tests the misconception that an HTTPS listener alone encrypts the entire path; candidates forget that the ALB-to-backend connection is separate and must also be configured for HTTPS.

How to eliminate wrong answers

Option A is wrong because an HTTP listener does not encrypt client-to-ALB traffic, and HTTP on port 80 to backends does not encrypt ALB-to-instance traffic. Option B is wrong because while the HTTPS listener encrypts client-to-ALB traffic, routing to backends over HTTP on port 80 leaves the ALB-to-instance leg unencrypted. Option D is wrong because ALB does not support TCP listeners (that is NLB), and even if it did, terminating TLS on the instances without an HTTPS listener on the ALB would not encrypt client-to-ALB traffic.

42
MCQeasy

A security engineer needs to block a specific range of malicious IP addresses from accessing an entire subnet within a VPC. The solution must ensure that the traffic is rejected before it reaches any EC2 instances. Which AWS feature should be used to implement this restriction?

A.Security Groups
B.Network Access Control Lists (NACLs)
C.AWS WAF
D.AWS Shield Standard
AnswerB

NACLs provide a layer of security at the subnet level and support both allow and deny rules. By placing a deny rule with a lower rule number than the default allow rule, the security engineer can effectively block the malicious IP range for all resources within that subnet.

Why this answer

Network ACLs are stateless, subnet-level firewalls that evaluate traffic before it reaches any EC2 instance, making them the correct tool to block a malicious IP range at the subnet boundary. Because NACLs support explicit deny rules with CIDR ranges, they can reject the traffic before it hits the instances.

Exam trap

SAA-C03 often tests the misconception that Security Groups can block specific IPs — they cannot, because they only support allow rules; candidates who forget this choose A instead of NACLs.

How to eliminate wrong answers

Option A is wrong because Security Groups are stateful, instance-level firewalls that only support allow rules — they cannot explicitly deny a specific IP range. Option C is wrong because AWS WAF operates at Layer 7 on CloudFront, ALB, or API Gateway and filters HTTP requests, not raw IP traffic at the subnet level. Option D is wrong because AWS Shield Standard only protects against DDoS attacks and does not allow custom IP blocking rules.

43
MCQeasy

A company is concerned that its database credentials, currently stored as environment variables in AWS Lambda, are not being rotated regularly. Which AWS service should the company use to securely store and automatically rotate these credentials?

A.AWS Systems Manager Parameter Store with SecureString parameters.
B.AWS Key Management Service (KMS) to encrypt the environment variables.
C.AWS Secrets Manager with its built-in rotation feature for Amazon RDS.
D.AWS Identity and Access Management (IAM) roles for the Lambda function.
AnswerC

AWS Secrets Manager provides native support for rotating credentials for RDS, Redshift, and DocumentDB. It can automatically update the password in the database and the secret value simultaneously, ensuring that the application always has access to current credentials without storing them in insecure environment variables.

Why this answer

AWS Secrets Manager is purpose-built for storing secrets and provides native, automatic rotation using Lambda rotation functions, including built-in templates for Amazon RDS, Aurora, Redshift, and DocumentDB credentials. It integrates with RDS so the database password and the secret are rotated together without application downtime. This directly satisfies the requirement to store credentials securely and rotate them automatically.

Exam trap

SAA-C03 often tests the Parameter Store vs Secrets Manager distinction, baiting candidates with SecureString encryption while ignoring that only Secrets Manager provides native automatic rotation.

How to eliminate wrong answers

Option A is wrong because Systems Manager Parameter Store SecureString encrypts values with KMS but has no native automatic rotation — you would have to build and schedule your own rotation Lambda, which does not meet the 'automatically rotate' requirement out of the box. Option B is wrong because KMS encrypts data but does not store or rotate application/database credentials; it is a key management service, not a secrets store. Option D is wrong because IAM roles grant temporary AWS API credentials to the Lambda function but do not manage or rotate the database username/password the application uses to connect to RDS.

44
Multi-Selecthard

A large corporation uses AWS Organizations to manage hundreds of accounts. The security team wants to ensure that no account can provision resources in unauthorized regions and that only approved AWS services can be used. Which TWO features should be used to enforce these constraints across the entire organization? (Select TWO.)

Select 2 answers
A.IAM Policies attached to each administrative user in every member account.
B.Service Control Policies (SCPs) applied to the root of the Organization.
C.AWS Resource Access Manager (RAM) to share authorized services across accounts.
D.AWS Config rules to automatically terminate resources in unauthorized regions.
E.SCPs with a Condition element to restrict the 'aws:RequestedRegion' key.
AnswersB, E

Service Control Policies (SCPs) can be applied at the organizational unit or account level to restrict the services and actions available to users. By using a Deny statement with a condition for specific regions, administrators can ensure that no resources are provisioned outside of authorized geographic areas.

Why this answer

Option B is correct because Service Control Policies (SCPs) applied at the organization root set the maximum available permissions for all accounts in the organization, so they can centrally deny access to unapproved AWS services across every member account. Option E is correct because an SCP with a Condition element using the aws:RequestedRegion global condition key can explicitly deny API calls made to regions outside the approved list, enforcing the region restriction organization-wide. Together, SCPs at the root and region-based conditions satisfy both requirements: restricting services and restricting regions for all accounts.

Option A is not appropriate because IAM policies in each member account are decentralized, must be maintained per account, and do not act as a guardrail against account administrators granting themselves broader permissions. Option C is incorrect because AWS Resource Access Manager (RAM) shares resources such as subnets or Transit Gateways between accounts; it does not restrict which services or regions can be used. Option D is incorrect because AWS Config rules detect and can remediate noncompliant resources after creation, but they do not prevent provisioning in unauthorized regions the way an SCP deny does.

Exam trap

SAA-C03 often tests the misconception that IAM policies or AWS Config can enforce organization-wide preventive controls, when only SCPs provide centralized, preventive permission boundaries.

45
Multi-Selectmedium

A web application is deployed on Amazon EC2 instances within a private subnet. The application must receive traffic from an Application Load Balancer (ALB) in a public subnet and connect to an Amazon RDS MySQL database in a different private subnet. Which TWO steps are required to secure this architecture using security groups?

Select 2 answers
A.Configure the EC2 security group to allow inbound traffic on port 80/443 from the ALB security group.
B.Configure the RDS security group to allow inbound traffic on port 3306 from the EC2 security group.
C.Configure the EC2 security group to allow inbound traffic from 0.0.0.0/0 on port 80 to handle web traffic.
D.Configure the RDS security group to allow outbound traffic to the EC2 instances on all ports.
E.Configure the ALB security group to allow inbound traffic from the EC2 security group on port 80.
AnswersA, B

Security groups should be configured to allow traffic only from specific sources using security group referencing. By allowing inbound traffic to the EC2 instances only from the ALB's security group, you ensure that the application cannot be accessed directly from other sources, even within the same VPC.

Why this answer

Option A is correct because the EC2 instances must accept HTTP/HTTPS traffic from the ALB, and referencing the ALB's security group as the source on ports 80/443 restricts inbound access to only that load balancer rather than the whole internet. Option B is correct because the application tier must reach the RDS MySQL database on its listener port 3306, and using the EC2 security group as the source in the RDS security group's inbound rule limits database access to only those application instances. Option C is wrong because allowing 0.0.0.0/0 on port 80 would expose the instances directly to the internet, defeating the purpose of placing them in a private subnet behind an ALB.

Option D is wrong because security groups are stateful, so return traffic for allowed inbound connections is automatically permitted and no outbound rule to the EC2 instances is needed; moreover, RDS does not initiate connections to the instances. Option E is wrong because it reverses the traffic direction: the ALB receives client traffic from the internet, not from the EC2 instances, so the ALB security group should allow inbound 80/443 from the internet (or appropriate clients), not from the EC2 security group.

Exam trap

SAA-C03 often tests whether candidates understand that security groups are stateful and can reference other security groups, luring them into picking CIDR-based rules (0.0.0.0/0) or unnecessary outbound rules.

46
MCQmedium

A developer needs to access an S3 bucket from an EC2 instance. For security best practices, the developer must avoid hardcoding long-term credentials on the instance. What is the most secure method to provide the necessary permissions?

A.Create an IAM user with S3 access and store the access key and secret key in a local configuration file.
B.Attach an IAM role to the EC2 instance with an S3 access policy.
C.Configure the S3 bucket policy to allow public read access to the specific EC2 instance's public IP address.
D.Modify the instance security group to allow all traffic to and from the S3 endpoint.
AnswerB

IAM roles provide temporary credentials via the AWS metadata service, which the SDK uses automatically. This method avoids hardcoding credentials on the disk, follows the principle of least privilege, and ensures that permissions are tied to the compute resource rather than a long-lived user identity.

Why this answer

Attaching an IAM role to the EC2 instance lets the instance obtain temporary, automatically rotated credentials via the Instance Metadata Service (IMDS), eliminating hardcoded long-term keys. The role's policy grants least-privilege S3 access, which is the AWS-recommended best practice for instance-to-service authentication.

Exam trap

SAA-C03 often tests the misconception that security groups or bucket policies tied to IPs can authorize EC2-to-S3 access, when the correct answer is always instance roles for credential-free, least-privilege access.

How to eliminate wrong answers

Option A is wrong because storing IAM user access keys in a local config file hardcodes long-term credentials, which can be leaked and must be manually rotated — exactly what the question says to avoid. Option C is wrong because allowing public read access based on an EC2 public IP is insecure, brittle (IPs change), and exposes the bucket to the internet. Option D is wrong because security groups control network traffic, not S3 API authorization; S3 access is governed by IAM policies, not security group rules.

47
MCQmedium

Refer to the exhibit. A solutions architect reviews the following IAM policy applied to a user. What is the effect of this policy when the user attempts to access an object in the bucket from an IP address of 198.51.100.5?

A.Access is allowed because the policy grants s3:GetObject permissions to the bucket.
B.Access is denied because the source IP address is not within the 203.0.113.0/24 range.
C.Access is allowed because there is no explicit Deny statement in the policy.
D.Access is denied because the policy does not include permissions for the s3:ListBucket action.
AnswerB

The policy includes an IpAddress condition that limits the Allow effect to the 203.0.113.0/24 subnet. Because the user's IP address (198.51.100.5) does not match this range, the policy does not provide the necessary permission to access the S3 object, resulting in an implicit deny.

Why this answer

The policy includes a condition that restricts access to the IP range 203.0.113.0/24. Since the user's IP address (198.51.100.5) is outside this range, the condition evaluates to false, and the Allow statement does not apply. Therefore, the request is implicitly denied because there is no other Allow statement that grants access.

Exam trap

SAA-C03 often tests the misconception that an Allow statement without an explicit Deny always grants access, ignoring the effect of condition keys like aws:SourceIp that can make the Allow ineffective.

How to eliminate wrong answers

Option A is wrong because the policy's Allow statement is conditional on the source IP being within 203.0.113.0/24; the condition fails for 198.51.100.5, so the grant does not apply. Option C is wrong because AWS IAM uses an implicit deny by default; even without an explicit Deny, the absence of a matching Allow results in denial. Option D is wrong because s3:ListBucket is not required to access an object; the s3:GetObject permission alone would suffice if the IP condition were met, but the failure is due to the IP restriction, not the missing ListBucket permission.

48
Multi-Selecthard

A company's public-facing application is experiencing a Distributed Denial of Service (DDoS) attack. The application is hosted on EC2 instances behind an Application Load Balancer (ALB). Which TWO AWS services or features can be used to mitigate this attack and protect the application?

Select 2 answers
A.AWS Shield Advanced for enhanced DDoS detection and mitigation.
B.AWS WAF with rate-based rules to block IP addresses with high request volumes.
C.Amazon GuardDuty to identify and block malicious traffic at the VPC level.
D.Amazon Inspector to scan EC2 instances for vulnerabilities during the attack.
E.AWS PrivateLink to hide the application from the public internet.
AnswersA, B

AWS Shield Advanced provides additional protections for resources like ALBs and CloudFront distributions. It offers 24/7 access to the AWS Shield Response Team (SRT) and provides more sophisticated detection mechanisms to identify and mitigate large-scale or complex DDoS attacks that target the application layer.

Why this answer

Protecting against DDoS attacks requires a multi-layered approach. AWS Shield provides automatic protection for all AWS customers, while Shield Advanced offers enhanced detection and mitigation for sophisticated attacks. AWS WAF complements this by allowing administrators to create rules that block malicious traffic patterns, such as SQL injection or high-volume IP addresses.

Exam trap

Candidates often confuse AWS Shield Standard with Advanced, or assume Security Groups can block DDoS attacks. Security Groups are stateful firewalls for instance-level traffic, not a solution for large-scale distributed volumetric DDoS mitigation.

49
Multi-Selectmedium

An architect is designing a secure VPC architecture. Which TWO actions should be taken to ensure the infrastructure is compliant with security best practices regarding network isolation?

Select 2 answers
A.Place all EC2 instances in the public subnet to maximize accessibility.
B.Use Network ACLs as a stateless firewall for subnet-level traffic control.
C.Configure Security Groups to allow all traffic (0.0.0.0/0) on all ports.
D.Implement Security Groups as stateful firewalls for instance-level traffic control.
E.Disable VPC Flow Logs to reduce the storage costs in S3.
AnswersB, D

Network ACLs act as a first line of defense at the subnet level. Because they are stateless, they require explicit rules for both inbound and outbound traffic, providing a robust way to block or allow traffic ranges before it ever reaches the individual EC2 instances residing within the subnet.

Why this answer

Option B is correct because Network ACLs are stateless, subnet-level firewalls that evaluate inbound and outbound rules independently, providing an additional layer of traffic control for network isolation in a VPC. Option D is correct because Security Groups are stateful, instance-level firewalls that automatically allow return traffic for permitted connections, which is a fundamental AWS best practice for controlling access to EC2 instances. Option A is incorrect because placing all EC2 instances in a public subnet exposes them directly to the internet and violates network isolation best practices; instances that don't need public access should reside in private subnets.

Option C is incorrect because allowing all traffic from 0.0.0.0/0 on all ports effectively disables firewall protection and is a severe security misconfiguration. Option E is incorrect because disabling VPC Flow Logs removes valuable network traffic visibility needed for monitoring, auditing, and incident response, and cost reduction should not come at the expense of security observability.

Exam trap

SAA-C03 often tests the confusion between stateful and stateless firewalls, and the misconception that Security Groups can deny traffic (they cannot).

50
MCQmedium

A healthcare company must store patient records in Amazon S3 for a minimum of 7 years to meet regulatory requirements. During this period, the records must not be deleted or modified by any user, including the root user. Which S3 feature should be used to enforce this?

A.S3 Versioning with MFA Delete
B.S3 Object Lock in Governance mode
C.S3 Object Lock in Compliance mode
D.S3 Lifecycle policy with an expiration of 7 years
AnswerC

Compliance mode ensures that an object version cannot be overwritten or deleted by any user, including the AWS account root user. The retention period is strictly enforced, and the mode cannot be changed or shortened, making it the correct choice for meeting high-bar regulatory standards.

Why this answer

S3 Object Lock provides Write-Once-Read-Many (WORM) protection. When configured in Compliance mode, an object version cannot be deleted or overwritten by any user, including the root user, for the duration of the retention period. This is the only way to satisfy strict regulatory requirements for data immutability.

Exam trap

Candidates often suggest S3 Lifecycle Policies. Lifecycle policies move or delete data based on age, but they do not prevent an administrator from manually deleting data before the time expires.

51
MCQmedium

A data analytics company stores massive amounts of data in Amazon S3. They need a way to automatically identify and flag sensitive data, such as Personally Identifiable Information (PII) or financial records, to ensure it is not being mishandled. Which AWS service is designed for this task?

A.Amazon GuardDuty
B.Amazon Macie
C.AWS Glue
D.Amazon Inspector
AnswerB

Amazon Macie is specifically built to discover and protect sensitive data at scale. It scans S3 buckets and identifies data types like credit card numbers, social security numbers, and API keys. This automation helps organizations understand their data exposure and implement appropriate security controls efficiently.

Why this answer

Amazon Macie is a fully managed data security and data privacy service. It uses machine learning and pattern matching to automatically discover and protect sensitive data in Amazon S3. Macie provides a dashboard and findings that alert the security team to PII, helping them maintain data privacy compliance.

Exam trap

Candidates often confuse Amazon Macie with AWS GuardDuty or IAM Access Analyzer, losing track of Macie's specific focus on S3 data discovery.

Ready to test yourself?

Try a timed practice session using only Design Secure Architectures questions.