Courseiva

SAA-C03 Design Secure Architectures Practice Question

A containerized service needs to read exactly one secret value from AWS Secrets Manager. The secret’s ARN is already known, and the secret is encrypted with the AWS-managed KMS key for Secrets Manager, so no separate KMS permissions are needed for this question. The service does not need to list secrets, create secrets, rotate them, or write updates. What is the most least-privilege IAM permission statement to grant the service role?

⚠ Common exam trap

Watch out — candidates often choose a broader permission like `secretsmanager:*` or `secretsmanager:ListSecrets` because they confuse the need to discover the secret with the need to read it, or they overlook that the ARN is already known, making list actions unnecessary.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Allow secretsmanager:GetSecretValue on the specific secret ARN only.

The service only needs to read a single secret value, and the least-privilege permission is to allow only the `secretsmanager:GetSecretValue` action on that specific secret's ARN. This grants exactly the required read access without any additional capabilities, adhering to the principle of least privilege. Since the secret is encrypted with the AWS-managed KMS key for Secrets Manager, no separate KMS permissions are needed, as the key policy automatically grants access to the Secrets Manager service.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Allow secretsmanager:GetSecretValue on the specific secret ARN only.

    Why this is correct

    For a read-only use case where the secret ARN is already known, the minimum required Secrets Manager action is secretsmanager:GetSecretValue. Scoping the resource to only that secret ARN minimizes blast radius if the role is compromised.

  • ✗

    Allow secretsmanager:* on all resources in the account.

    Why it's wrong here

    Granting secretsmanager:* on all resources is an administrative privilege, not a read action: it allows creating, updating, rotating, and deleting every secret in the account. A container retrieving one known secret needs only GetSecretValue, so this wildcard policy needlessly exposes the entire Secrets Manager estate and maximizes the blast radius if the container's credentials are compromised.

  • ✗

    Allow secretsmanager:ListSecrets so the service can discover the secret ARN at runtime.

    Why it's wrong here

    ListSecrets only returns secret metadata (names, ARNs, tags, descriptions); it does not return the secret value, so the container would still need GetSecretValue to read the actual secret. The secret ARN is already configured in the container, so runtime discovery is unnecessary and granting ListSecrets lets the role probe the account for all secret names and metadata, broadening the attack surface without supporting the described read.

  • ✗

    Allow secretsmanager:PutSecretValue so the service can retrieve and update the secret value.

    Why it's wrong here

    PutSecretValue is a write operation that overwrites the secret's encrypted value; it has no role in a read-only retrieval workflow. Granting it would let the container unintentionally corrupt the secret or disrupt dependent applications, while also violating least privilege because the stated requirement only asks to read exactly one secret.

About these practice questions

This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.