Courseiva
Design Secure ArchitectureshardMultiple ChoiceObjective-mapped

SAA-C03 Design Secure Architectures Practice Question

A platform team lets application teams create IAM roles in member accounts through Infrastructure as Code. Security says every new role must stay within a centrally approved permission ceiling, even if someone later attaches broader managed policies or inline policies. Which control should be used to enforce that maximum permission set?

⚠ Common exam trap

Test-takers frequently confuse service control policies (SCPs) with permissions boundaries: SCPs apply to all principals in an account and cannot be used to set a per-role permission ceiling, while permissions boundaries are specifically designed for that granular control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Attach a permissions boundary to each role so the role can never exceed the approved ceiling.

A permissions boundary is an AWS IAM feature that sets the maximum permissions an IAM role can have. When attached to a role, any policy that grants permissions beyond the boundary is effectively ignored, ensuring the role cannot exceed the approved permission ceiling even if broader managed or inline policies are later attached. This directly enforces the security requirement without restricting the application teams' ability to create roles via Infrastructure as Code.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Use an AWS Organizations service control policy to grant the role all needed permissions directly.

    Why it's wrong here

    An SCP sets the maximum permissions an account can use, but it does not define a per-role ceiling that survives future policy attachment changes. It is the wrong tool for limiting an individual IAM role’s permissions boundary.

  • Attach a permissions boundary to each role so the role can never exceed the approved ceiling.

    Why this is correct

    A permissions boundary is specifically designed to cap the maximum permissions a role can ever receive, regardless of what identity-based policies are attached later. If a developer adds a broader managed policy or inline policy, the effective permissions still cannot exceed the boundary. This makes it the best fit for delegated role creation with a centrally approved ceiling.

  • Use a resource-based policy on Amazon S3 to restrict the permissions that IAM roles can receive.

    Why it's wrong here

    Resource policies control access to the resource they are attached to, not the maximum permissions a role can hold across AWS services. They do not provide a general guardrail for IAM role creation or future policy attachment.

  • Require temporary STS session policies whenever the role is assumed.

    Why it's wrong here

    Session policies can further reduce permissions for a specific session, but they depend on every caller behaving correctly each time the role is assumed. They are not a durable organizational ceiling for all future role sessions or policy attachments.

About these practice questions

This SAA-C03 question is part of Courseiva's 302-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.