SAA-C03 Design Secure Architectures Practice Question
A company uses AWS Organizations and has separate development, test, and production accounts. The security team wants to ensure that no one in the sandbox organizational unit can disable AWS CloudTrail or delete the central audit bucket, even if an account administrator creates permissive IAM policies later. Which control should they use?
⚠ Common exam trap
A common mix-up: candidates confuse service control policies with IAM permission boundaries or resource-based policies, thinking that a bucket policy or permission boundary can prevent service-level actions like disabling CloudTrail, when only an SCP can enforce such restrictions across all principals in an entire OU.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a service control policy on the sandbox organizational unit to deny the prohibited actions.
Service control policies (SCPs) are the correct mechanism because they act as a centralized guardrail at the AWS Organizations level, setting maximum permissions for all accounts in an organizational unit (OU). Even if an account administrator creates permissive IAM policies later, an SCP that explicitly denies disabling CloudTrail or deleting the central audit bucket will override those permissions, ensuring the security team's requirements are enforced across the sandbox OU.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Attach an identity-based policy in each account that denies CloudTrail changes.
Why it's wrong here
An identity-based policy that denies CloudTrail changes is only in effect for the specific IAM principal to which it is attached, and it can be bypassed by any principal that can create or modify IAM entities. Because developers in a sandbox account typically need some IAM permissions, they could call iam:CreatePolicy or iam:CreateUser to create a new principal that lacks the deny statement, or the account administrator could simply attach a separate allow policy to themselves. Moreover, the AWS account root user is not bound by an identity-based policy, so any action taken via root would not be constrained.
When this WOULD be correct
This option would be correct if the question asked for a way to restrict CloudTrail changes for a specific IAM user or role within a single account, without needing to enforce the restriction across multiple accounts or prevent override by an account admin.
- ✓
Use a service control policy on the sandbox organizational unit to deny the prohibited actions.
Why this is correct
Service control policies are the correct governance mechanism for setting guardrails across multiple accounts in AWS Organizations. An SCP can explicitly deny sensitive actions such as disabling CloudTrail or deleting the audit bucket, and those denies apply even if administrators create local IAM policies that would otherwise allow the actions. SCPs do not grant permissions by themselves; they only constrain what account principals can ever do within the OU.
- ✗
Create an S3 bucket policy that allows only the audit team role to delete objects.
Why it's wrong here
An S3 bucket policy that limits deletion to the audit team role protects only the contents of the audit trail bucket, not the CloudTrail service itself. A sandbox principal with cloudtrail:StopLogging or cloudtrail:DeleteTrail can stop trail delivery before any object is deleted, and nothing in the bucket policy prevents them from altering the trail configuration or turning off log file validation. The bucket policy therefore addresses the log object, not the logging control system, leaving the prohibited CloudTrail actions unrestricted.
When this WOULD be correct
This would be correct in a scenario where the requirement is to restrict deletion of objects within a specific S3 bucket to only an audit team role, while other users can still read or write. For example, a question asking 'How to ensure only the audit team can delete audit logs from the central bucket?'
- ✗
Apply a permission boundary to each IAM user in the sandbox accounts.
Why it's wrong here
Permission boundaries are attached to individual IAM users or roles and only cap that principal's effective permissions, so they cannot restrain other principals such as the account root user, service-linked roles, or roles that developers create with a permissive trust policy. Even if every existing IAM user has a boundary, sandbox administrators who hold iam:PassRole or iam:CreateRole permission can spin up new roles outside the boundary's scope. Thus, permission boundaries are a useful per-entity guardrail but fail to enforce a consistent, account-wide control plane.
When this WOULD be correct
A question where the requirement is to restrict the maximum permissions for specific IAM users or roles within an account, such as limiting developers to read-only access while allowing them to create their own IAM roles within those bounds.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SAA-C03 exam frequently reuses these exact scenarios with slightly different constraints.
✓Use a service control policy on the sandbox organizational unit to deny the prohibited actions.Correct answer▾
Why this is correct
Service control policies are the correct governance mechanism for setting guardrails across multiple accounts in AWS Organizations. An SCP can explicitly deny sensitive actions such as disabling CloudTrail or deleting the audit bucket, and those denies apply even if administrators create local IAM policies that would otherwise allow the actions. SCPs do not grant permissions by themselves; they only constrain what account principals can ever do within the OU.
✗Attach an identity-based policy in each account that denies CloudTrail changes.Wrong answer — click to see why▾
Why this is wrong here
Identity-based policies can be overridden by a more permissive policy attached by an account administrator, so they do not provide a guaranteed guardrail across all accounts in the organizational unit.
★ When this WOULD be the correct answer
This option would be correct if the question asked for a way to restrict CloudTrail changes for a specific IAM user or role within a single account, without needing to enforce the restriction across multiple accounts or prevent override by an account admin.
Why candidates choose this
Candidates may think identity-based policies are sufficient for restricting actions, but they overlook that account administrators can attach permissive policies that override the deny, making SCPs necessary for organization-wide enforcement.
✗Create an S3 bucket policy that allows only the audit team role to delete objects.Wrong answer — click to see why▾
Why this is wrong here
An S3 bucket policy only controls access to the bucket itself, not the ability to disable CloudTrail or delete the bucket from other services like IAM or CloudTrail. It does not prevent an account administrator from disabling CloudTrail entirely or deleting the bucket via the console or API.
★ When this WOULD be the correct answer
This would be correct in a scenario where the requirement is to restrict deletion of objects within a specific S3 bucket to only an audit team role, while other users can still read or write. For example, a question asking 'How to ensure only the audit team can delete audit logs from the central bucket?'
Why candidates choose this
Candidates may think a bucket policy is sufficient to protect the audit bucket, overlooking that CloudTrail can be disabled independently or that the bucket itself can be deleted via other means.
✗Apply a permission boundary to each IAM user in the sandbox accounts.Wrong answer — click to see why▾
Why this is wrong here
Permission boundaries limit the maximum permissions for IAM users but do not prevent account administrators from creating permissive IAM policies that bypass the boundary, nor do they protect against actions taken by the root user or other principals. They are not effective for preventing CloudTrail disabling or bucket deletion across all users in an account.
★ When this WOULD be the correct answer
A question where the requirement is to restrict the maximum permissions for specific IAM users or roles within an account, such as limiting developers to read-only access while allowing them to create their own IAM roles within those bounds.
Why candidates choose this
Candidates may confuse permission boundaries with service control policies, thinking they can centrally enforce restrictions on all users, but boundaries only apply to IAM principals and can be overridden by account administrators.
Analysis generated from the official SAA-C03blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
About these practice questions
Courseiva writes every SAA-C03 question from scratch — 935 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.