Courseiva

SAA-C03 Design Secure Architectures Practice Question

A SaaS vendor’s automation account in Account B needs to assume a role in a customer account in Account A to read a specific S3 bucket and publish a deployment status file. The customer is worried about confused deputy attacks because multiple customers use the same vendor software. Which trust-policy design best meets the requirement?

⚠ Common exam trap

It's easy for candidates to confuse MFA or permissions boundaries as solutions for the confused deputy problem, when in fact only the `sts:ExternalId` condition directly mitigates this specific threat by providing a customer-specific identifier in the trust policy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Allow only the vendor’s specific IAM principal to assume the role and require a unique sts:ExternalId condition.

The `sts:ExternalId` condition is specifically designed to prevent the confused deputy problem in cross-account role assumptions. By requiring a unique external ID that only the customer knows, the customer ensures that the vendor's automation can only assume the role when acting on behalf of that specific customer, even if multiple customers use the same vendor software.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Allow the Account B root principal to assume the role if the caller knows the role ARN.

    Why it's wrong here

    This would work technically, but it is far too broad and does not protect against confused deputy abuse. Any principal in Account B that can reach the role could potentially use it, which violates the customer’s security requirement.

  • ✓

    Allow only the vendor’s specific IAM principal to assume the role and require a unique sts:ExternalId condition.

    Why this is correct

    This is the standard confused deputy protection pattern for third-party cross-account access. The trust policy limits who can call AssumeRole, and the sts:ExternalId condition lets the customer require a customer-specific value that the vendor must supply. That prevents another customer or a malicious party from reusing the same role ARN successfully.

  • ✗

    Attach a permissions boundary to the role so that the vendor cannot exceed the approved permissions.

    Why it's wrong here

    A permissions boundary caps the maximum permissions the role can have once assumed, but it does not restrict which principals can call sts:AssumeRole. In a confused deputy attack, an unintended principal could still assume the role and perform any actions allowed by the boundary, so the boundary does not protect against the threat. The trust policy with a specific principal and sts:ExternalId condition is the control that gates who can assume the role, not a permissions boundary.

  • ✗

    Require MFA for the role assumption because it ensures only the vendor’s production automation can use the role.

    Why it's wrong here

    Requiring MFA is nonsensical for non-human automation and does not mitigate the confused deputy risk. MFA only verifies that the caller possesses a second factor, but if the trust policy allows broad principals, any of them with valid MFA could potentially assume the role. Moreover, the vendor's production automation credentials are not tied to a human identity, so MFA cannot be practically enforced; the correct pattern is to use a unique sts:ExternalId condition in the trust policy to prevent reuse across customers.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SAA-C03 question from scratch — 935 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.