SAA-C03 Design Secure Architectures Practice Question
A partner company needs read-only access to reports in an S3 bucket for a image sharing application. The partner has its own AWS account. What is the most secure scalable access pattern?
⚠ Common exam trap
A common mix-up: candidates choose sharing IAM access keys (Option B) because it seems simpler, but the SAA-C03 exam emphasizes using IAM roles and resource-based policies for cross-account access to avoid long-term credential management and improve security.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a bucket policy that grants the partner role least-privilege access to the required prefix
It uses a resource-based bucket policy that grants the partner's AWS account (via its IAM role) least-privilege read-only access to a specific prefix. This avoids sharing long-term credentials, leverages AWS's cross-account trust mechanism, and ensures the partner's access is controlled through their own IAM roles, which is the most secure and scalable pattern for cross-account S3 access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Make the objects public and rely on difficult-to-guess object names
Why it's wrong here
Making object names unguessable is not a security boundary—it is security by obscurity. If the bucket policy permits public read (effectively from the Principal '*'), any object in the bucket can be fetched by anyone who obtains or guesses its URL, and those URLs can leak via logs, HTTP referrers, or browser history. There is no way to revoke access for a single partner, enforce least privilege per prefix, or audit who accessed which report.
- ✗
Create an IAM user in the company account and share the access keys
Why it's wrong here
Sharing an IAM user's access keys with a partner creates long-term, shared credentials that live entirely in your own account. This approach fails to attribute actions to specific individuals in the partner organization, complicates key rotation and deprovisioning, and risks exposure if the keys are transmitted or stored insecurely. Even if the keys are only given to one partner, there is no scoping to a particular role or prefix beyond what the IAM user's policy permits, and the partner account gains no self-service control over access.
- ✗
Copy the objects to a public website bucket
Why it's wrong here
A public website bucket (enabled with static website hosting) turns the bucket into an internet-facing origin where every object is served as anonymous content. This is an all-or-nothing exposure: it makes the reports accessible to any user on the public internet, not just the partner, and offers no support for authentication, IAM principals, or per-object access controls. It also bypasses S3's Block Public Access safeguards and makes the data vulnerable to search engines and automated crawlers.
- ✓
Create a bucket policy that grants the partner role least-privilege access to the required prefix
Why this is correct
A bucket policy is an S3 resource-based policy that can grant cross-account access to a specific IAM role in the partner account. By scoping the Principal to the partner's role ARN, the Action to s3:GetObject (and s3:ListBucket if needed), and the Resource to the exact prefix path, you implement least-privilege access. The partner's role must also have a corresponding identity-based policy allowing the S3 actions, but the bucket policy is what authorizes access across accounts without storing shared keys.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.