SAA-C03 Design Secure Architectures Practice Question
A company needs to give an external auditing firm read-only access to specific objects in an Amazon S3 bucket for 30 days. The firm has its own AWS account and should not receive long-term credentials. The company wants to minimize the blast radius if the firm's account is compromised. Which two steps should the company take? (Choose two.)
⚠ Common exam trap
The trap here is thinking that cross-account S3 access requires making the bucket public or disabling Block Public Access, when role assumption with a scoped policy is the intended mechanism.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an IAM role in the company account with a trust policy that allows the auditing firm's AWS account to assume it, and attach a policy granting s3:GetObject on the specific object prefix.
Cross-account temporary access is best implemented with an IAM role in the resource account that the external account assumes. Scoping the role policy to the specific prefix and requiring sts:AssumeRole with a maximum session duration and an external ID limits what a compromised external account can do and prevents the confused deputy problem. Long-term IAM users and public buckets fail the security goals.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create an IAM user in the company account for the auditing firm and email the access key and secret key to the firm's security contact.
Why it's wrong here
Creating an IAM user with access keys issues long-term credentials, which the requirement explicitly forbids. Emailing keys increases exposure risk and makes rotation and revocation harder. This option also does not limit the blast radius well because the keys can be used until deleted or rotated.
- ✓
Create an IAM role in the company account with a trust policy that allows the auditing firm's AWS account to assume it, and attach a policy granting s3:GetObject on the specific object prefix.
Why this is correct
Cross-account access without long-term credentials is achieved with an IAM role that the external account assumes. Scoping the role policy to s3:GetObject on a specific prefix limits the blast radius if the external account is compromised. This is the standard AWS pattern for temporary cross-account access and meets the read-only requirement.
- ✗
Attach an S3 bucket policy that grants s3:GetObject to the auditing firm's IAM user ARN, and disable S3 Block Public Access to allow the cross-account policy to work.
Why it's wrong here
S3 Block Public Access does not need to be disabled for cross-account access to a non-public bucket. Granting access to an IAM user ARN in another account is possible, but it is less clean than role assumption and can be brittle if the firm changes users. This option also introduces an unnecessary and risky change to public access settings.
- ✗
Make the S3 bucket public and share the object URLs with the auditing firm so no AWS credentials are needed.
Why it's wrong here
A public bucket exposes the objects to anyone with the URL, not just the auditing firm, and violates the least privilege and blast radius requirements. It also cannot be scoped to a specific external account. This approach removes credential management but at an unacceptable security cost and does not meet the read-only scoped access goal.
- ✓
Require the auditing firm to call sts:AssumeRole and use the resulting temporary credentials, and set a maximum session duration and an external ID in the trust policy.
Why this is correct
Using sts:AssumeRole provides temporary credentials that expire, which avoids long-term secrets. Setting a maximum session duration limits how long a compromised session is usable, and an external ID protects against the confused deputy problem. This complements the role creation step and satisfies the temporary access and blast radius goals.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.