SAA-C03 Design Secure Architectures Practice Question
A CI pipeline needs to upload build artifacts only to s3://ci-artifacts/uploads/*. You also want the pipeline to list only objects under uploads/ to verify that the upload succeeded. Which IAM policy approach is the best fit for least privilege?
⚠ Common exam trap
A common mix-up: candidates confuse s3:GetObject with s3:ListBucket for verifying uploads, or they forget to restrict the s3:prefix condition on ListBucket, leading to overly permissive policies.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Allow s3:PutObject on arn:aws:s3:::ci-artifacts/uploads/* and allow s3:ListBucket on arn:aws:s3:::ci-artifacts with a condition that restricts s3:prefix to uploads/.
It grants the minimum required permissions: s3:PutObject on the specific uploads/ path for uploading artifacts, and s3:ListBucket on the bucket with a condition restricting the s3:prefix to uploads/ to list only objects under that prefix. This follows the least privilege principle by scoping both actions to the exact resources needed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Allow s3:PutObject on arn:aws:s3:::ci-artifacts/uploads/* and allow s3:ListBucket on arn:aws:s3:::ci-artifacts with a condition that restricts s3:prefix to uploads/.
Why this is correct
This scopes object writes to only the uploads/ prefix (resource-level restriction for s3:PutObject) and scopes object listing to only that same prefix by restricting the ListBucket request via the s3:prefix condition key (bucket-level authorization for s3:ListBucket).
- ✗
Allow s3:PutObject on arn:aws:s3:::ci-artifacts/* and allow s3:ListBucket on arn:aws:s3:::ci-artifacts without any prefix condition.
Why it's wrong here
This policy grants s3:PutObject on arn:aws:s3:::ci-artifacts/*, which permits writes to the bucket root and to every prefix, not just uploads/, thereby expanding the upload scope far beyond the required path. Additionally, s3:ListBucket is allowed on the bucket ARN with no s3:prefix condition, so the principal can list every object in the entire bucket rather than being restricted to uploads/. Combined, these permissions violate least privilege by giving broad write and read access that the CI pipeline does not need.
When this WOULD be correct
This option would be correct if the requirement was to allow the pipeline to upload artifacts to any location under the bucket and list all objects (e.g., for general bucket management). For example, a CI pipeline that needs to upload build outputs to various folders and verify the entire bucket contents.
- ✗
Allow s3:GetObject on arn:aws:s3:::ci-artifacts/uploads/* so the pipeline can confirm artifacts exist.
Why it's wrong here
s3:GetObject is a read-only action that retrieves an object's contents or metadata; it grants no ability to perform s3:PutObject, so the pipeline cannot upload artifacts. Even if the intent were to verify artifact existence, GetObject on uploads/* requires knowing the exact object key, which is not the stated requirement. This option therefore completely fails to authorize the write operation needed by the CI pipeline.
When this WOULD be correct
A scenario where the pipeline needs to download or read the content of uploaded artifacts (e.g., for validation or processing) would require s3:GetObject on the upload path.
- ✗
Allow s3:PutObject on arn:aws:s3:::ci-artifacts/uploads/* and also allow s3:DeleteObject on arn:aws:s3:::ci-artifacts/uploads/*.
Why it's wrong here
While this option correctly scopes s3:PutObject to the uploads/ prefix, it adds s3:DeleteObject on the same prefix, which is not necessary for uploading artifacts. PutObject already creates or overwrites objects; DeleteObject is a separate destructive action that increases the risk of accidental or malicious removal of build artifacts. Least privilege dictates granting only the minimum actions needed, and the pipeline only needs to write objects and verify them via a scoped ListBucket, not delete them.
When this WOULD be correct
This option would be correct if the pipeline also needed to delete old or failed uploads from the uploads/ prefix to manage storage or clean up after a failed build.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SAA-C03 exam frequently reuses these exact scenarios with slightly different constraints.
✓Allow s3:PutObject on arn:aws:s3:::ci-artifacts/uploads/* and allow s3:ListBucket on arn:aws:s3:::ci-artifacts with a condition that restricts s3:prefix to uploads/.Correct answer▾
Why this is correct
This scopes object writes to only the uploads/ prefix (resource-level restriction for s3:PutObject) and scopes object listing to only that same prefix by restricting the ListBucket request via the s3:prefix condition key (bucket-level authorization for s3:ListBucket).
✗Allow s3:PutObject on arn:aws:s3:::ci-artifacts/* and allow s3:ListBucket on arn:aws:s3:::ci-artifacts without any prefix condition.Wrong answer — click to see why▾
Why this is wrong here
Option B allows s3:PutObject on all objects under ci-artifacts (not just uploads/), violating the least privilege requirement to restrict uploads to uploads/*. Additionally, it grants s3:ListBucket without a prefix condition, allowing listing of all objects in the bucket, which is broader than needed.
★ When this WOULD be the correct answer
This option would be correct if the requirement was to allow the pipeline to upload artifacts to any location under the bucket and list all objects (e.g., for general bucket management). For example, a CI pipeline that needs to upload build outputs to various folders and verify the entire bucket contents.
Why candidates choose this
Candidates may think that allowing PutObject on the entire bucket is simpler and still meets the upload requirement, overlooking the need to restrict to uploads/. They may also underestimate the risk of granting ListBucket without a prefix condition.
✗Allow s3:GetObject on arn:aws:s3:::ci-artifacts/uploads/* so the pipeline can confirm artifacts exist.Wrong answer — click to see why▾
Why this is wrong here
The pipeline needs to upload artifacts (PutObject) and list objects (ListBucket) to verify uploads, not download them. GetObject is for reading object content, which is not required for verification.
★ When this WOULD be the correct answer
A scenario where the pipeline needs to download or read the content of uploaded artifacts (e.g., for validation or processing) would require s3:GetObject on the upload path.
Why candidates choose this
Candidates may confuse 'verifying upload succeeded' with needing to read the object, or think that listing requires GetObject permission.
✗Allow s3:PutObject on arn:aws:s3:::ci-artifacts/uploads/* and also allow s3:DeleteObject on arn:aws:s3:::ci-artifacts/uploads/*.Wrong answer — click to see why▾
Why this is wrong here
Option D includes s3:DeleteObject, which is not required for the pipeline's tasks of uploading and listing artifacts. Granting unnecessary permissions violates the principle of least privilege.
★ When this WOULD be the correct answer
This option would be correct if the pipeline also needed to delete old or failed uploads from the uploads/ prefix to manage storage or clean up after a failed build.
Why candidates choose this
Candidates may think that including DeleteObject is harmless or might be needed for cleanup, overlooking that the question explicitly requires only upload and list capabilities.
Analysis generated from the official SAA-C03blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 935 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.