SAA-C03 Design Secure Architectures Practice Question
Developers for a financial reporting platform need temporary elevated access to production resources for troubleshooting. The security team wants approvals, expiry, and audit logging. Which approach is best?
⚠ Common exam trap
A common mix-up: candidates think IAM roles with a trust policy and `sts:AssumeRole` are sufficient, but without IAM Identity Center's permission sets and time-bound controls, they lack the centralized approval workflow and automatic expiry that the question explicitly requires.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use IAM Identity Center permission sets with time-bound access processes and CloudTrail auditing
IAM Identity Center (formerly AWS SSO) allows you to define permission sets with time-bound access, ensuring that developers receive temporary elevated permissions that automatically expire. Combined with AWS CloudTrail, all API calls made during the troubleshooting session are logged for audit, meeting the security team's requirements for approvals, expiry, and audit logging.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use IAM Identity Center permission sets with time-bound access processes and CloudTrail auditing
Why this is correct
IAM Identity Center permission sets let you define job-function-based roles (e.g., AdministratorAccess) and assign them to users or groups for a specific session duration or via time-bound assignment processes, such as requesting access for a ticket window. This approach keeps temporary credentials short-lived, limits standing privilege, and integrates with CloudTrail so every federated console or API call is attributed to a specific identity for audited troubleshooting sessions.
- ✗
Disable CloudTrail during troubleshooting
Why it's wrong here
Disabling CloudTrail during troubleshooting removes the audit log that records who made what API call and when, which cripples post-incident analysis and makes it impossible to prove a clean root cause. It also violates security best practices and many compliance frameworks (e.g., PCI-DSS, SOX) that mandate continuous logging, so even though it shortens noisy logs, it unacceptably degrades accountability and investigation capability.
- ✗
Create shared administrator access keys for the team
Why it's wrong here
Shared administrator access keys are long-term, static credentials that lack any identity attribution—everyone using them appears as the same principal, so you cannot determine which developer performed a destructive action or when a key leaked. Because the keys are never rotated and are shared, the blast radius is catastrophic if they are compromised, and there is no mechanism to enforce individual fine-grained permissions or revoke a single person's access, making this an unacceptable security practice.
- ✗
Attach AdministratorAccess permanently to every developer role
Why it's wrong here
Permanently attaching AdministratorAccess to every developer role grants complete, unchanging privileges regardless of task, which directly violates least privilege and creates standing high-risk permissions that expand the attack surface. Any developer or compromised session can immediately perform irreversible actions (e.g., deleting S3 buckets, modifying IAM policies) without additional controls, and because the access is permanent, there is no time bound or need-to-know check.
Go deeper
Related to this question
About these practice questions
This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.