Courseiva
Design Secure Architectures →mediumMultiple Choice

SAA-C03 Design Secure Architectures Practice Question

A partner company needs read-only access to reports in an S3 bucket for a image sharing application. The partner has its own AWS account. What is the most secure scalable access pattern?

⚠ Common exam trap

A common mix-up: candidates choose sharing IAM access keys (Option B) because it seems simpler, but the SAA-C03 exam emphasizes using IAM roles and resource-based policies for cross-account access to avoid long-term credential management and improve security.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a bucket policy that grants the partner role least-privilege access to the required prefix

It uses a resource-based bucket policy that grants the partner's AWS account (via its IAM role) least-privilege read-only access to a specific prefix. This avoids sharing long-term credentials, leverages AWS's cross-account trust mechanism, and ensures the partner's access is controlled through their own IAM roles, which is the most secure and scalable pattern for cross-account S3 access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Make the objects public and rely on difficult-to-guess object names

    Why it's wrong here

    Making object names unguessable is not a security boundary—it is security by obscurity. If the bucket policy permits public read (effectively from the Principal '*'), any object in the bucket can be fetched by anyone who obtains or guesses its URL, and those URLs can leak via logs, HTTP referrers, or browser history. There is no way to revoke access for a single partner, enforce least privilege per prefix, or audit who accessed which report.

  • ✗

    Create an IAM user in the company account and share the access keys

    Why it's wrong here

    Sharing an IAM user's access keys with a partner creates long-term, shared credentials that live entirely in your own account. This approach fails to attribute actions to specific individuals in the partner organization, complicates key rotation and deprovisioning, and risks exposure if the keys are transmitted or stored insecurely. Even if the keys are only given to one partner, there is no scoping to a particular role or prefix beyond what the IAM user's policy permits, and the partner account gains no self-service control over access.

  • ✗

    Copy the objects to a public website bucket

    Why it's wrong here

    A public website bucket (enabled with static website hosting) turns the bucket into an internet-facing origin where every object is served as anonymous content. This is an all-or-nothing exposure: it makes the reports accessible to any user on the public internet, not just the partner, and offers no support for authentication, IAM principals, or per-object access controls. It also bypasses S3's Block Public Access safeguards and makes the data vulnerable to search engines and automated crawlers.

  • ✓

    Create a bucket policy that grants the partner role least-privilege access to the required prefix

    Why this is correct

    A bucket policy is an S3 resource-based policy that can grant cross-account access to a specific IAM role in the partner account. By scoping the Principal to the partner's role ARN, the Action to s3:GetObject (and s3:ListBucket if needed), and the Resource to the exact prefix path, you implement least-privilege access. The partner's role must also have a corresponding identity-based policy allowing the S3 actions, but the bucket policy is what authorizes access across accounts without storing shared keys.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.