Courseiva
Design Secure Architectures →mediumMultiple Choice

SAA-C03 Design Secure Architectures Practice Question

Exhibit

Cross-account access attempt:

Account A:
- EC2 instance profile role: arn:aws:iam::111122223333:role/AppRole
- Identity policy allows s3:GetObject on arn:aws:s3:::shared-data-bucket/*

Account B:
- Bucket policy currently allows the account root principal only
- Application log shows: AccessDenied when calling GetObject on shared-data-bucket
- Security requirement: no static credentials; access must be revocable centrally

Based on the exhibit, what is the most appropriate fix so the workload in Account A can access the S3 bucket in Account B without using long-lived access keys?

⚠ Common exam trap

Watch out — candidates often confuse SCPs with resource-based policies or assume that attaching a managed policy to an instance profile automatically grants cross-account access, overlooking the need for explicit trust and bucket policies in the target account.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an IAM role in Account B, trust Account A's AppRole to assume it with STS, and then access the bucket using temporary credentials.

It uses AWS Security Token Service (STS) to allow the workload in Account A to assume an IAM role in Account B, obtaining temporary credentials that grant access to the S3 bucket. This eliminates the need for long-lived access keys and follows the principle of least privilege, as the role can be scoped to specific S3 actions and resources.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create an IAM role in Account B, trust Account A's AppRole to assume it with STS, and then access the bucket using temporary credentials.

    Why this is correct

    Assuming a role in the target account is a clean cross-account pattern that uses temporary credentials instead of static keys. The trust policy in Account B controls who may assume the role, and the role in B can then be given the exact S3 permissions needed. This is easy to revoke centrally by changing the trust relationship or role policy.

  • ✗

    Attach AmazonS3FullAccess to the instance profile role in Account A and keep using the same direct access path.

    Why it's wrong here

    Attaching AmazonS3FullAccess to the instance profile role in Account A only broadens the source identity's permissions and leaves the same direct access path in place; it does not modify the bucket policy in Account B, which must contain an explicit allow for the cross-account principal. S3 access to another account's bucket is a union of the identity-based policy and the resource-based bucket policy, so without a bucket policy permit, the request will still be denied regardless of how permissive the IAM role is. This approach also violates least privilege by granting every S3 action to the instance, making it an insecure and incomplete fix.

    When this WOULD be correct

    Option B would be correct if the S3 bucket is in the same account as the workload (Account A) and the goal is to grant full S3 access to an EC2 instance using an instance profile role, without requiring cross-account access.

  • ✗

    Add an SCP to Account A that allows S3 actions against buckets in Account B.

    Why it's wrong here

    An SCP is an AWS Organizations policy that acts as a permission guardrail for principals within Account A; it can only restrict what Account A's IAM principals are allowed to do, never grant permissions to resources owned by another account. Cross-account S3 access is authorized by the target bucket's bucket policy plus the source principal's IAM permissions, and an SCP does not create the required trust relationship or alter Account B's bucket policy. Therefore adding an SCP would not enable the request and could even further restrict existing access if not carefully scoped.

    When this WOULD be correct

    An SCP would be correct if the question asked: 'How can an organization administrator prevent all accounts in the organization from deleting an S3 bucket in a specific account?' In that case, adding an SCP that denies s3:DeleteBucket actions for that bucket would be appropriate.

  • ✗

    Enable S3 versioning on the bucket so cross-account requests are automatically trusted.

    Why it's wrong here

    S3 versioning stores multiple versions of an object to protect against accidental deletion or overwrite, but it has no effect on IAM authentication or the authorization decisions made when an Account A principal attempts to access an Account B bucket. Cross-account requests are allowed only when the destination bucket policy explicitly grants the source account or role and the source identity also has the necessary s3: actions in its own policy. Enabling versioning addresses data protection, not inter-account trust, so it cannot resolve the authorization failure.

    When this WOULD be correct

    A question asks how to protect against accidental deletion or overwriting of objects in an S3 bucket. Enabling versioning would be the correct answer because it allows recovery of previous object versions.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SAA-C03 exam frequently reuses these exact scenarios with slightly different constraints.

✓Create an IAM role in Account B, trust Account A's AppRole to assume it with STS, and then access the bucket using temporary credentials.Correct answer▾

Why this is correct

Assuming a role in the target account is a clean cross-account pattern that uses temporary credentials instead of static keys. The trust policy in Account B controls who may assume the role, and the role in B can then be given the exact S3 permissions needed. This is easy to revoke centrally by changing the trust relationship or role policy.

✗Attach AmazonS3FullAccess to the instance profile role in Account A and keep using the same direct access path.Wrong answer — click to see why▾

Why this is wrong here

Option B is wrong because attaching AmazonS3FullAccess to the instance profile role in Account A does not grant cross-account access to an S3 bucket in Account B. The bucket's bucket policy must explicitly allow the role from Account A, and using long-lived access keys is not avoided.

★ When this WOULD be the correct answer

Option B would be correct if the S3 bucket is in the same account as the workload (Account A) and the goal is to grant full S3 access to an EC2 instance using an instance profile role, without requiring cross-account access.

Why candidates choose this

Candidates may think that attaching a full-access policy to the instance profile role is sufficient for any S3 access, overlooking the need for cross-account bucket policies and the requirement to avoid long-lived keys.

✗Add an SCP to Account A that allows S3 actions against buckets in Account B.Wrong answer — click to see why▾

Why this is wrong here

SCPs (Service Control Policies) are used to restrict permissions in AWS Organizations accounts, not to grant cross-account access. They cannot allow actions; they only deny or limit permissions. Thus, adding an SCP to Account A does not enable the workload to access the S3 bucket in Account B.

★ When this WOULD be the correct answer

An SCP would be correct if the question asked: 'How can an organization administrator prevent all accounts in the organization from deleting an S3 bucket in a specific account?' In that case, adding an SCP that denies s3:DeleteBucket actions for that bucket would be appropriate.

Why candidates choose this

Candidates may confuse SCPs with resource-based policies or IAM policies, thinking SCPs can grant cross-account access, or they may overestimate the scope of SCPs as a general permission-granting mechanism.

✗Enable S3 versioning on the bucket so cross-account requests are automatically trusted.Wrong answer — click to see why▾

Why this is wrong here

Enabling S3 versioning does not grant cross-account access permissions; it only preserves object versions. Cross-account access requires explicit IAM policies and bucket policies, not versioning.

★ When this WOULD be the correct answer

A question asks how to protect against accidental deletion or overwriting of objects in an S3 bucket. Enabling versioning would be the correct answer because it allows recovery of previous object versions.

Why candidates choose this

Candidates may mistakenly think versioning enables cross-account trust or that it automatically resolves access control issues, confusing versioning with bucket policies or resource-based permissions.

Analysis generated from the official SAA-C03blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 935 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.