SAA-C03 Design Secure Architectures Practice Question
A partner company needs read-only access to reports in an S3 bucket for a B2B file exchange site. The partner has its own AWS account. What is the most secure scalable access pattern? The design must avoid adding custom operational scripts.
⚠ Common exam trap
Watch out — candidates often choose Option B (IAM user with shared keys) because it seems straightforward, but they overlook the security risk of long-term credentials and the operational burden of key rotation, which violates the 'most secure scalable' and 'avoid custom scripts' requirements.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a bucket policy that grants the partner role least-privilege access to the required prefix
It uses a bucket policy with a principal ARN for the partner's AWS account, granting read-only access to a specific prefix. This is secure (no public exposure), scalable (no per-user credentials to manage), and avoids custom scripts by leveraging native AWS IAM and S3 policy evaluation. The partner can use their own IAM roles to access the bucket without sharing long-term access keys.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Make the objects public and rely on difficult-to-guess object names
Why it's wrong here
Making objects public with difficult-to-guess names is security through obscurity, not access control. Any user who obtains the URL can read the object, and object names can leak through logs, browser history, or shared links. S3 public access is not scoped to a principal or prefix; once an object is public, every AWS account and internet user can read it, so the partner's access cannot be limited to a specific role or prefix and least privilege is impossible.
- ✗
Create an IAM user in the company account and share the access keys
Why it's wrong here
Creating an IAM user and sharing access keys gives the partner a permanent, long-lived credential that is shared across all partner staff, destroying individual accountability and audit trails. These keys cannot be rotated automatically, cannot be scoped to a temporary session, and if leaked they become an unrestricted backdoor for any operation the user's policy allows. This approach also violates the recommendation to use IAM roles and temporary credentials for cross-account access.
- ✓
Create a bucket policy that grants the partner role least-privilege access to the required prefix
Why this is correct
A bucket policy that sets the Principal element to the partner role's ARN (e.g., arn:aws:iam::123456789012:role/PartnerRole) and the Resource to backup/prefix/* grants read-only access to only that prefix while keeping the bucket private. This resource-based policy is evaluated together with the partner role's own identity-based policy, so both administrators can enforce least privilege, and the source account can revoke access centrally by editing the bucket policy. Using a role also leverages temporary credentials and CloudTrail auditing.
- ✗
Copy the objects to a public website bucket
Why it's wrong here
Copying the objects to a public website bucket exposes the reports to the entire internet because S3 static website endpoints serve content anonymously over HTTP and do not evaluate IAM or bucket policies. You would not only grant the partner access but also every user who can discover the URL, and you would have to maintain a duplicate, possibly stale copy. This approach defeats least privilege and is far less secure than a private bucket with a resource-based policy.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SAA-C03 question from scratch — 935 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.