SAA-C03 Design Secure Architectures Practice Question
Exhibit
AWS Organizations policy summary:
Root OU: Full access
Production OU: SCP attached
SCP content:
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Deny",
"Action": ["ec2:CreateSnapshot", "ec2:DeleteSnapshot"],
"Resource": "*"
}
]
}
CloudTrail event:
- userIdentity: arn:aws:iam::444455556666:role/OpsAdmin
- eventName: CreateSnapshot
- errorCode: AccessDenied
- errorMessage: action denied by organizations service control policyBased on the exhibit, why is the IAM role still receiving AccessDenied even though it has AdministratorAccess attached?
⚠ Common exam trap
Test-takers frequently assume AdministratorAccess grants full permissions unconditionally, forgetting that SCPs can impose a higher-level deny that overrides any IAM allow, especially in AWS Organizations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The SCP is acting as a maximum permission guardrail, so its explicit deny overrides the IAM allow.
B is correct because Service Control Policies (SCPs) act as a maximum permission guardrail in AWS Organizations. Even if an IAM role has the AdministratorAccess policy attached, an SCP with an explicit deny on the ec2:CreateSnapshot action will override that allow, resulting in an AccessDenied error. SCPs are evaluated after IAM policies, and an explicit deny in an SCP cannot be overridden by any IAM allow.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AdministratorAccess is always evaluated before SCPs, so the SCP is ignored in production accounts.
Why it's wrong here
AWS does not evaluate IAM policies before SCPs; instead, the effective permission is the intersection of all applicable policy types, with any explicit deny taking precedence. AdministratorAccess grants broad allow permissions, but it cannot override an explicit deny from a service control policy because the SCP defines the maximum permissible scope for the account. In production accounts or any other account, the SCP is never ignored, and its deny remains authoritative.
When this WOULD be correct
This option would be correct if the question described a scenario where an SCP allows an action but an IAM policy denies it, and the question asks about evaluation order. In that case, IAM deny overrides SCP allow, so AdministratorAccess (IAM allow) would not be evaluated before the SCP deny.
- ✓
The SCP is acting as a maximum permission guardrail, so its explicit deny overrides the IAM allow.
Why this is correct
SCPs set the outer boundary for permissions in an account or OU. They do not grant access, but they can block actions even when the IAM role has AdministratorAccess. The explicit deny in the SCP is therefore the reason CreateSnapshot fails. To allow the operation, the organization must change the SCP or move the account out of the restrictive scope.
- ✗
The role needs a session duration of at least 12 hours before SCPs stop applying.
Why it's wrong here
The duration of a role session only limits how long temporary credentials remain valid; it has no bearing on which actions those credentials are permitted to perform. SCPs are evaluated against every request from any principal in the account, regardless of whether that session lasts one hour or one week. An explicit SCP deny applies from the moment the session starts, so extending the session to 12 hours would still not allow CreateSnapshot.
When this WOULD be correct
If a question described a role that assumes a long-running session and the error is 'Session token expired' or 'AccessDenied' due to temporary credentials timing out, then increasing session duration (e.g., to 12 hours) would resolve it.
- ✗
The account needs an AWS Config rule to approve the snapshot action before IAM can work.
Why it's wrong here
AWS Config is a service for recording resource configurations, evaluating compliance rules, and detecting drift; it does not participate in the IAM authorization decision process. The request for CreateSnapshot is accepted or denied solely based on the combined effect of SCPs, IAM policies, permission boundaries, and session policies. Adding a Config rule might identify noncompliant snapshots after the fact, but it cannot pre-approve or override an SCP deny.
When this WOULD be correct
In a scenario where an IAM role is allowed by an SCP but still denied access to a specific resource, and the question states that AWS Config rules are used to enforce compliance by automatically revoking permissions via a custom Lambda function, then D could be correct if the Config rule is misconfigured or not triggering the remediation.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SAA-C03 exam frequently reuses these exact scenarios with slightly different constraints.
✓The SCP is acting as a maximum permission guardrail, so its explicit deny overrides the IAM allow.Correct answer▾
Why this is correct
SCPs set the outer boundary for permissions in an account or OU. They do not grant access, but they can block actions even when the IAM role has AdministratorAccess. The explicit deny in the SCP is therefore the reason CreateSnapshot fails. To allow the operation, the organization must change the SCP or move the account out of the restrictive scope.
✗AdministratorAccess is always evaluated before SCPs, so the SCP is ignored in production accounts.Wrong answer — click to see why▾
Why this is wrong here
SCPs are evaluated before IAM policies and can explicitly deny actions, overriding any IAM allow, including AdministratorAccess. The statement that AdministratorAccess is always evaluated before SCPs is incorrect.
★ When this WOULD be the correct answer
This option would be correct if the question described a scenario where an SCP allows an action but an IAM policy denies it, and the question asks about evaluation order. In that case, IAM deny overrides SCP allow, so AdministratorAccess (IAM allow) would not be evaluated before the SCP deny.
Why candidates choose this
Candidates may confuse the evaluation order of IAM policies and SCPs, mistakenly thinking that IAM policies are always evaluated first or that AdministratorAccess is an exception to SCPs.
✗The role needs a session duration of at least 12 hours before SCPs stop applying.Wrong answer — click to see why▾
Why this is wrong here
Session duration does not affect SCP evaluation; SCPs apply to all principals regardless of session length. The AccessDenied is due to an SCP explicitly denying the action, not a session duration issue.
★ When this WOULD be the correct answer
If a question described a role that assumes a long-running session and the error is 'Session token expired' or 'AccessDenied' due to temporary credentials timing out, then increasing session duration (e.g., to 12 hours) would resolve it.
Why candidates choose this
Candidates may confuse session duration limits with SCP evaluation, thinking that longer sessions bypass SCPs, or they may misremember that SCPs only apply to short-lived sessions.
✗The account needs an AWS Config rule to approve the snapshot action before IAM can work.Wrong answer — click to see why▾
Why this is wrong here
AWS Config rules can trigger remediation actions or evaluate compliance, but they do not grant or deny IAM permissions. The AccessDenied error is caused by an SCP explicit deny, not by the absence of a Config rule.
★ When this WOULD be the correct answer
In a scenario where an IAM role is allowed by an SCP but still denied access to a specific resource, and the question states that AWS Config rules are used to enforce compliance by automatically revoking permissions via a custom Lambda function, then D could be correct if the Config rule is misconfigured or not triggering the remediation.
Why candidates choose this
Candidates may confuse AWS Config's compliance evaluation with IAM authorization, thinking that Config rules act as a gatekeeper for API actions, similar to how SCPs or resource-based policies work.
Analysis generated from the official SAA-C03blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
About these practice questions
Courseiva writes every SAA-C03 question from scratch — 935 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.