Courseiva
Design Secure Architectures →mediumMultiple Choice

SAA-C03 Design Secure Architectures Practice Question

Account A has an IAM role named FinanceDataRole that is assumed by a principal in Account B. The role’s trust policy includes a condition requiring sts:ExternalId to equal "Fin-2026-Q2". A developer in Account B calls AssumeRole but receives an error: AccessDenied: ExternalId mismatch. The security team requires that you do not remove the ExternalId condition. What is the correct remediation?

⚠ Common exam trap

Test-takers frequently think the ExternalId is automatically passed or that the error is due to permission issues (like KMS or session duration), when in fact the developer must explicitly include the correct ExternalId in the AssumeRole API call.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Update the AssumeRole call in Account B to include sts:ExternalId="Fin-2026-Q2" exactly as required.

The error 'AccessDenied: ExternalId mismatch' occurs because the AssumeRole API call from Account B does not include the required sts:ExternalId parameter. The trust policy on the FinanceDataRole explicitly requires this parameter to match 'Fin-2026-Q2' as a security measure to prevent the confused deputy problem. Option B is correct because the developer must pass the exact ExternalId value in the AssumeRole request to satisfy the condition and successfully assume the role.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Add kms:Decrypt to the developer’s IAM policy so KMS can validate the ExternalId during AssumeRole.

    Why it's wrong here

    Adding kms:Decrypt to the developer's IAM policy cannot influence STS trust policy evaluation because the sts:ExternalId condition is checked by the STS service against the value passed in the AssumeRole request, not against KMS permissions. KMS permissions govern encryption and decryption operations on AWS KMS keys, which are entirely unrelated to the trust relationship between accounts. Even with kms:Decrypt, the missing or mismatched ExternalId in the AssumeRole call will still cause AccessDenied.

  • ✓

    Update the AssumeRole call in Account B to include sts:ExternalId="Fin-2026-Q2" exactly as required.

    Why this is correct

    To satisfy the role's trust policy, the AssumeRole request from Account B must explicitly include the parameter sts:ExternalId with the exact value "Fin-2026-Q2". STS evaluates this parameter against the StringEquals condition on sts:ExternalId in the trust policy; if it matches, the policy condition passes and STS issues temporary credentials. Supplying any other value or omitting the parameter will cause the AssumeRole call to be denied.

  • ✗

    Increase the role’s MaxSessionDuration to reduce authentication failures.

    Why it's wrong here

    MaxSessionDuration only controls the maximum validity period of the temporary credentials after STS successfully issues them; it plays no role in whether the AssumeRole request is authorized at the moment the trust policy is evaluated. Since the ExternalId condition fails, STS denies the request before a session is even created, so increasing the session duration cannot reduce authentication failures.

  • ✗

    Remove the ExternalId condition from the trust policy to allow all AssumeRole requests.

    Why it's wrong here

    Removing the ExternalId condition from the trust policy would let the AssumeRole request pass without the required value, but it would directly violate the security requirement to protect against the confused-deputy problem. This condition is specifically designed to verify that the caller possesses the shared secret known only to the intended external account; deleting it weakens the cross-account trust boundary and leaves the role exposed to malicious third parties.

About these practice questions

Courseiva writes every SAA-C03 question from scratch — 935 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.