SAA-C03 Design Secure Architectures Practice Question
A microservice needs to read exactly one secret value from AWS Secrets Manager. Which IAM permission statement provides the best least-privilege approach to allow the microservice to retrieve that secret value?
⚠ Common exam trap
Candidates often choose a broad wildcard or 'all resources' permission (Option A or C) thinking it simplifies management, but the SAA-C03 exam consistently tests the principle of least privilege by requiring the most restrictive resource and action scope.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Allow secretsmanager:GetSecretValue only on the specific secret ARN required by the service
It grants the minimum necessary permission—secretsmanager:GetSecretValue—scoped to the exact Amazon Resource Name (ARN) of the secret the microservice needs. This follows the AWS least-privilege principle by restricting access to a single action on a single resource, preventing the microservice from reading other secrets even if compromised.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Allow secretsmanager:GetSecretValue on all secrets using Resource: "*"
Why it's wrong here
Using Resource: "*" for secretsmanager:GetSecretValue grants the microservice permission to retrieve the plaintext value of every secret in the AWS account, not just the one it requires. This includes secrets owned by other workloads, environments, or teams, creating an unnecessarily large blast radius if the microservice is compromised. Even if the secret is encrypted with an AWS-managed key, the IAM statement itself is still overly permissive because it does not restrict the resource to a specific secret ARN, violating least privilege. To properly limit access, the resource must be scoped to the exact ARN of the intended secret.
- ✓
Allow secretsmanager:GetSecretValue only on the specific secret ARN required by the service
Why this is correct
Restricting the Resource to the exact Secrets Manager secret ARN limits retrieval to only that secret. This minimizes exposure and follows least-privilege practices. (If the secret is encrypted with a customer-managed KMS key, additional KMS permissions may be required for decrypting the ciphertext, but the Secrets Manager permission itself should still be scoped tightly.)
- ✗
Allow secretsmanager:* on the secret name prefix using a wildcard pattern
Why it's wrong here
Granting secretsmanager:* on a secret name prefix with a wildcard pattern is doubly over-permissive: it authorizes all Secrets Manager actions, including destructive ones like DeleteSecret, RestoreSecret, and PutSecretValue, and it matches any secret whose name shares that prefix. This means the microservice could not only read secrets it should not access, but also modify or delete secrets, potentially causing data loss or security compromise. A wildcard prefix does not reliably isolate a single secret, especially since secret ARNs contain a random suffix that is not fully predictable. Instead, the policy should allow only GetSecretValue (or the minimum required actions) and target the complete ARN of the specific secret.
- ✗
Allow secretsmanager:GetSecretValue on the AWS account root ARN
Why it's wrong here
The AWS account root ARN is not the correct resource type for Secrets Manager secrets. Because IAM resource matching requires the action to be permitted on the correct Secrets Manager secret resource ARN, this statement would not provide the intended access to the secret value.
Go deeper
Related to this question
About these practice questions
One of 935 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.