Courseiva

SAA-C03 Design Secure Architectures Practice Question

A team wants to delegate IAM management to developers, but must ensure developers can never grant themselves permissions beyond a specific limit. Which AWS mechanism best matches this requirement?

⚠ Common exam trap

Many candidates confuse service control policies (SCPs) with permission boundaries, as both can limit permissions, but SCPs apply account-wide and cannot be selectively applied to only developers' IAM users, while permission boundaries are attached directly to the IAM entity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use an IAM permission boundary on roles/users that developers create, so the developers’ effective permissions are capped by the boundary policy.

IAM permission boundaries are the correct mechanism because they allow a developer to create IAM roles or users, but explicitly cap the maximum permissions those entities can have. The boundary policy acts as a ceiling, so even if a developer attaches a permissive managed policy, the effective permissions are the intersection of the boundary and the attached policy. This directly enforces the requirement that developers cannot grant themselves permissions beyond a specific limit.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use an IAM permission boundary on roles/users that developers create, so the developers’ effective permissions are capped by the boundary policy.

    Why this is correct

    Permission boundaries constrain the maximum permissions that an identity can receive. Even if developers attach an identity policy that allows broader actions, the effective permissions are limited to the intersection of the identity policy and the boundary.

  • ✗

    Rely only on their IAM managed policies and instruct developers to self-check against internal guidelines.

    Why it's wrong here

    Relying solely on managed policies and asking developers to self-check is a procedural guideline, not an enforceable security control. Even if the IAM managed policies are carefully written, developers who can create or update policies can attach any permitted managed policy to themselves or to roles they manage, potentially exceeding the intended maximum permissions. Without a permission boundary, there is no technical mechanism that caps the effective permissions, making the system dependent on developer discipline and error-prone.

    When this WOULD be correct

    This option would be correct in a scenario where the question asks for a non-technical, process-based approach to manage permissions, such as 'Which method relies on developer compliance with written policies?' or 'Which approach is suitable for a small team with high trust and no need for automated controls?'

  • ✗

    Use a service control policy (SCP) that applies only to the developers’ IAM users in the account.

    Why it's wrong here

    SCPs are evaluated at the organization/account level and constrain allowed API actions for principal types across affected accounts/OUs. They are not the most direct tool for capping an individual principal’s maximum effective permissions in the way permission boundaries do (and SCPs are not designed for per-identity “maximum permission” limits).

    When this WOULD be correct

    If the question required restricting permissions for all principals in an AWS account (e.g., to enforce a maximum permission boundary for the entire account), an SCP would be the correct mechanism. For example: 'A company wants to ensure no IAM user or role in the account can access a specific service, regardless of IAM policies.'

  • ✗

    Use a KMS key policy to restrict IAM actions, because IAM actions can be controlled with KMS.

    Why it's wrong here

    KMS key policies govern cryptographic key usage (for example, Encrypt/Decrypt) and do not control whether a principal is authorized to grant or perform IAM permissions. KMS does not function as an IAM permissions cap mechanism.

    When this WOULD be correct

    A question that asks: 'Which mechanism restricts which IAM users can use a specific KMS key for encryption operations?' — then a KMS key policy would be correct because it directly controls access to the key.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SAA-C03 exam frequently reuses these exact scenarios with slightly different constraints.

✓Use an IAM permission boundary on roles/users that developers create, so the developers’ effective permissions are capped by the boundary policy.Correct answer▾

Why this is correct

Permission boundaries constrain the maximum permissions that an identity can receive. Even if developers attach an identity policy that allows broader actions, the effective permissions are limited to the intersection of the identity policy and the boundary.

✗Rely only on their IAM managed policies and instruct developers to self-check against internal guidelines.Wrong answer — click to see why▾

Why this is wrong here

Option B relies on manual self-policing without any technical enforcement, which cannot prevent developers from granting themselves permissions beyond the specified limit. AWS IAM has no built-in mechanism to enforce internal guidelines automatically.

★ When this WOULD be the correct answer

This option would be correct in a scenario where the question asks for a non-technical, process-based approach to manage permissions, such as 'Which method relies on developer compliance with written policies?' or 'Which approach is suitable for a small team with high trust and no need for automated controls?'

Why candidates choose this

Candidates may think that clear guidelines and self-checks are sufficient for compliance, underestimating the need for technical enforcement to prevent privilege escalation in IAM.

✗Use a service control policy (SCP) that applies only to the developers’ IAM users in the account.Wrong answer — click to see why▾

Why this is wrong here

Service control policies (SCPs) apply to all IAM users and roles in an AWS account, not just to specific developers' IAM users. SCPs cannot target individual users; they apply at the account, OU, or organization level.

★ When this WOULD be the correct answer

If the question required restricting permissions for all principals in an AWS account (e.g., to enforce a maximum permission boundary for the entire account), an SCP would be the correct mechanism. For example: 'A company wants to ensure no IAM user or role in the account can access a specific service, regardless of IAM policies.'

Why candidates choose this

Candidates may confuse SCPs with IAM permission boundaries, thinking SCPs can be applied to individual users. They might also believe SCPs are a fine-grained control for specific IAM entities, when in reality SCPs are account-level guardrails.

✗Use a KMS key policy to restrict IAM actions, because IAM actions can be controlled with KMS.Wrong answer — click to see why▾

Why this is wrong here

KMS key policies control access to KMS keys, not IAM actions. They cannot restrict IAM permissions or prevent developers from granting themselves elevated IAM privileges.

★ When this WOULD be the correct answer

A question that asks: 'Which mechanism restricts which IAM users can use a specific KMS key for encryption operations?' — then a KMS key policy would be correct because it directly controls access to the key.

Why candidates choose this

Candidates may confuse KMS key policies with IAM policies, thinking that since KMS integrates with IAM, its key policies can also control IAM actions, or they may misremember that KMS can be used for authorization beyond encryption.

Analysis generated from the official SAA-C03blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.