mediummultiple choiceObjective-mapped

A SaaS vendor needs temporary access to an S3 bucket in your AWS account to read customer exports. The vendor will assume an IAM role you created. During integration testing, the vendor reports that their AssumeRole requests succeed, but your security team is concerned about the possibility of confused-deputy attacks. Which trust policy approach most directly mitigates this risk?

Question 1mediummultiple choice
Full question →

A SaaS vendor needs temporary access to an S3 bucket in your AWS account to read customer exports. The vendor will assume an IAM role you created. During integration testing, the vendor reports that their AssumeRole requests succeed, but your security team is concerned about the possibility of confused-deputy attacks. Which trust policy approach most directly mitigates this risk?

Answer choices

Why each option matters

Good practice is not just finding the correct option. The wrong answers often show the exact trap the exam wants you to fall into.

A

Best answer

Add an sts:ExternalId condition to the role trust policy that must match the unique external ID you provide to the vendor.

The sts:ExternalId condition is a common protection against confused-deputy scenarios in cross-account role assumption. It ensures that only principals who know the unique external ID can successfully assume the role. This mitigates a third party tricking the vendor’s identity into assuming your role, even if they can call AssumeRole.

B

Distractor review

Require the vendor to use the same MFA device serial number as your internal administrators in the trust policy.

Trust policies can check conditions related to MFA in some contexts, but matching your internal MFA device serial to an external vendor is impractical and not the primary confused-deputy mitigation. External ID was designed specifically for this cross-account vendor role assumption pattern.

C

Distractor review

Remove the role’s permissions policy and rely only on the S3 bucket policy to validate the caller.

Relying solely on the bucket policy does not address the confused-deputy risk in role assumption. Also, a missing permissions policy may break legitimate access. External ID is the relevant trust policy mitigation for limiting which assumers can obtain credentials.

D

Distractor review

Allow sts:AssumeRole from the vendor account root principal without restricting to the vendor’s specific IAM role.

Allowing root principal broadly increases risk and does not mitigate confused-deputy attacks. The trust policy should be as specific as possible, and External ID provides a targeted protection against attackers misusing the vendor’s access.

Common exam trap

Common exam trap: answer the scenario, not the keyword

Many certification questions include familiar terms but test a specific constraint. Read the exact wording before choosing an answer that is generally true but wrong for this case.

Technical deep dive

How to think about this question

This question should be treated as a scenario, not a definition check. Identify the problem, the constraint and the best action. Then compare each option against those facts.

KKey Concepts to Remember

  • Read the scenario before looking for a memorised answer.
  • Find the constraint that changes the correct option.
  • Eliminate answers that are true in general but not in this case.
  • Use explanations to understand the rule behind the answer.

TExam Day Tips

  • Underline the problem statement mentally.
  • Watch for words such as best, first, most likely and least administrative effort.
  • Review why wrong options are wrong, not only why the correct option is correct.

Related practice questions

Related SAA-C03 practice-question pages

Use these pages to review the topic behind this question. This is how one missed question becomes focused revision.

More questions from this exam

Keep practising from the same exam bank, or move into a focused topic page if this question exposed a weak area.

FAQ

Questions learners often ask

What does this SAA-C03 question test?

Read the scenario before looking for a memorised answer.

What is the correct answer to this question?

The correct answer is: Add an sts:ExternalId condition to the role trust policy that must match the unique external ID you provide to the vendor. — In cross-account vendor integrations, the confused-deputy problem can occur when a third party tricks a vendor into assuming your role without having the right context. AWS recommends using sts:ExternalId in the IAM role trust policy as a shared secret-like value. By requiring the vendor to supply the correct ExternalId, only the intended vendor integration can successfully assume the role. This improves security even if other principals can call AssumeRole to the same role endpoint. Why others are wrong: B is impractical and not the standard mitigation for confused-deputy in role trust. C shifts responsibility to bucket policy and ignores the trust-time risk. D increases exposure by trusting the vendor account broadly; it also does not prevent confused-deputy. External ID directly targets the trust-policy acceptance condition that prevents unintended role assumption.

What should I do if I get this SAA-C03 question wrong?

Then try more questions from the same exam bank and focus on understanding why the wrong options are tempting.

Discussion

Loading comments…

Sign in to join the discussion.