Courseiva
Design Secure Architectures →mediumMultiple Select

SAA-C03 Design Secure Architectures Practice Question

A company needs to give an external auditing firm read-only access to specific objects in an Amazon S3 bucket for 30 days. The firm has its own AWS account and should not receive long-term credentials. The company wants to minimize the blast radius if the firm's account is compromised. Which two steps should the company take? (Choose two.)

⚠ Common exam trap

The trap here is thinking that cross-account S3 access requires making the bucket public or disabling Block Public Access, when role assumption with a scoped policy is the intended mechanism.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an IAM role in the company account with a trust policy that allows the auditing firm's AWS account to assume it, and attach a policy granting s3:GetObject on the specific object prefix.

Cross-account temporary access is best implemented with an IAM role in the resource account that the external account assumes. Scoping the role policy to the specific prefix and requiring sts:AssumeRole with a maximum session duration and an external ID limits what a compromised external account can do and prevents the confused deputy problem. Long-term IAM users and public buckets fail the security goals.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create an IAM user in the company account for the auditing firm and email the access key and secret key to the firm's security contact.

    Why it's wrong here

    Creating an IAM user with access keys issues long-term credentials, which the requirement explicitly forbids. Emailing keys increases exposure risk and makes rotation and revocation harder. This option also does not limit the blast radius well because the keys can be used until deleted or rotated.

  • ✓

    Create an IAM role in the company account with a trust policy that allows the auditing firm's AWS account to assume it, and attach a policy granting s3:GetObject on the specific object prefix.

    Why this is correct

    Cross-account access without long-term credentials is achieved with an IAM role that the external account assumes. Scoping the role policy to s3:GetObject on a specific prefix limits the blast radius if the external account is compromised. This is the standard AWS pattern for temporary cross-account access and meets the read-only requirement.

  • ✗

    Attach an S3 bucket policy that grants s3:GetObject to the auditing firm's IAM user ARN, and disable S3 Block Public Access to allow the cross-account policy to work.

    Why it's wrong here

    S3 Block Public Access does not need to be disabled for cross-account access to a non-public bucket. Granting access to an IAM user ARN in another account is possible, but it is less clean than role assumption and can be brittle if the firm changes users. This option also introduces an unnecessary and risky change to public access settings.

  • ✗

    Make the S3 bucket public and share the object URLs with the auditing firm so no AWS credentials are needed.

    Why it's wrong here

    A public bucket exposes the objects to anyone with the URL, not just the auditing firm, and violates the least privilege and blast radius requirements. It also cannot be scoped to a specific external account. This approach removes credential management but at an unacceptable security cost and does not meet the read-only scoped access goal.

  • ✓

    Require the auditing firm to call sts:AssumeRole and use the resulting temporary credentials, and set a maximum session duration and an external ID in the trust policy.

    Why this is correct

    Using sts:AssumeRole provides temporary credentials that expire, which avoids long-term secrets. Setting a maximum session duration limits how long a compromised session is usable, and an external ID protects against the confused deputy problem. This complements the role creation step and satisfies the temporary access and blast radius goals.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.