Courseiva
Design Secure Architectures →mediumMultiple Choice

SAA-C03 Design Secure Architectures Practice Question

Developers for a customer analytics portal need temporary elevated access to production resources for troubleshooting. The security team wants approvals, expiry, and audit logging. Which approach is best?

⚠ Common exam trap

Many exam-takers confuse IAM users with IAM Identity Center, or think that simply enabling CloudTrail (without a proper access control mechanism) is sufficient, but the question specifically requires time-bound access and approvals, which only a centralized identity solution like IAM Identity Center provides.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use IAM Identity Center permission sets with time-bound access processes and CloudTrail auditing

AWS IAM Identity Center (formerly AWS SSO) allows you to define permission sets that grant temporary, time-bound elevated access to production resources. Combined with AWS CloudTrail, every access attempt is logged for audit, meeting the security team's requirements for approvals, expiry, and audit logging. This approach follows the principle of least privilege and ensures that elevated permissions are not permanent.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disable CloudTrail during troubleshooting

    Why it's wrong here

    Disabling CloudTrail during troubleshooting removes the audit trail that records API calls, user identities, and resource changes, making root-cause analysis and security investigations impossible. CloudTrail is a detective control that should remain enabled precisely when issues arise, since its logs provide the timeline needed to correlate events and identify misconfigurations or unauthorized actions. Temporarily disabling it also leaves a gap in compliance evidence, undermining any later attempt to prove what occurred.

  • ✗

    Attach AdministratorAccess permanently to every developer role

    Why it's wrong here

    Permanently attaching AdministratorAccess to every developer role grants full, standing administrative privileges, which violates least privilege and drastically increases blast radius if a developer's credentials are compromised. Developers typically need only scoped permissions to specific services or resource tags, so broad access also masks misconfigurations and makes it harder to enforce separation of duties. This approach eliminates the need for temporary elevation but at the cost of persistent, unmonitored high-risk permissions across the entire team.

  • ✓

    Use IAM Identity Center permission sets with time-bound access processes and CloudTrail auditing

    Why this is correct

    IAM Identity Center permission sets allow you to assign role-based permissions (e.g., AdministratorAccess) to users or groups for a defined session duration, often combined with temporary elevation workflows that require approval and expire automatically. By coupling these time-bound assignments with CloudTrail auditing, every privileged action is attributable to a specific federated user and can be reviewed for anomalies. This reduces standing privilege, supports just-in-time access, and gives the team the temporary administrative power they need without permanently widening the security posture.

  • ✗

    Create shared administrator access keys for the team

    Why it's wrong here

    Creating shared administrator access keys for the team removes individual accountability because multiple developers can silently use the same credentials, making it impossible to determine who performed a destructive action. Long-term access keys are a primary target for exfiltration; if one is exposed, an attacker gains persistent administrative access, and rotating the key would disrupt every developer relying on it. This directly contradicts temporary access needs and auditing requirements, so it is both a security and an operational anti-pattern.

About these practice questions

This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.