Courseiva

SAA-C03 Design Secure Architectures Practice Question

A microservice needs to read exactly one secret value from AWS Secrets Manager. Which IAM permission statement provides the best least-privilege approach to allow the microservice to retrieve that secret value?

⚠ Common exam trap

Candidates often choose a broad wildcard or 'all resources' permission (Option A or C) thinking it simplifies management, but the SAA-C03 exam consistently tests the principle of least privilege by requiring the most restrictive resource and action scope.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Allow secretsmanager:GetSecretValue only on the specific secret ARN required by the service

It grants the minimum necessary permission—secretsmanager:GetSecretValue—scoped to the exact Amazon Resource Name (ARN) of the secret the microservice needs. This follows the AWS least-privilege principle by restricting access to a single action on a single resource, preventing the microservice from reading other secrets even if compromised.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Allow secretsmanager:GetSecretValue on all secrets using Resource: "*"

    Why it's wrong here

    Using Resource: "*" for secretsmanager:GetSecretValue grants the microservice permission to retrieve the plaintext value of every secret in the AWS account, not just the one it requires. This includes secrets owned by other workloads, environments, or teams, creating an unnecessarily large blast radius if the microservice is compromised. Even if the secret is encrypted with an AWS-managed key, the IAM statement itself is still overly permissive because it does not restrict the resource to a specific secret ARN, violating least privilege. To properly limit access, the resource must be scoped to the exact ARN of the intended secret.

  • ✓

    Allow secretsmanager:GetSecretValue only on the specific secret ARN required by the service

    Why this is correct

    Restricting the Resource to the exact Secrets Manager secret ARN limits retrieval to only that secret. This minimizes exposure and follows least-privilege practices. (If the secret is encrypted with a customer-managed KMS key, additional KMS permissions may be required for decrypting the ciphertext, but the Secrets Manager permission itself should still be scoped tightly.)

  • ✗

    Allow secretsmanager:* on the secret name prefix using a wildcard pattern

    Why it's wrong here

    Granting secretsmanager:* on a secret name prefix with a wildcard pattern is doubly over-permissive: it authorizes all Secrets Manager actions, including destructive ones like DeleteSecret, RestoreSecret, and PutSecretValue, and it matches any secret whose name shares that prefix. This means the microservice could not only read secrets it should not access, but also modify or delete secrets, potentially causing data loss or security compromise. A wildcard prefix does not reliably isolate a single secret, especially since secret ARNs contain a random suffix that is not fully predictable. Instead, the policy should allow only GetSecretValue (or the minimum required actions) and target the complete ARN of the specific secret.

  • ✗

    Allow secretsmanager:GetSecretValue on the AWS account root ARN

    Why it's wrong here

    The AWS account root ARN is not the correct resource type for Secrets Manager secrets. Because IAM resource matching requires the action to be permitted on the correct Secrets Manager secret resource ARN, this statement would not provide the intended access to the secret value.

About these practice questions

One of 935 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.