passdrill

IAM & Security

24 cards · AWS SAA-C03 · answer each one, then read the explanation. Your score tallies below. Looking for IAM Identity Center vs SAML federation vs Cognito identity pools, compared? Read the explainer.

0 / 24 answered · 0 correct

AWS SAA-C03 · IAM & Security · Card 001/024 easy

A developer's IAM user has two identity-based policies attached. One policy allows s3:GetObject on a specific bucket; the other explicitly denies s3:GetObject on that same bucket. No service control policy, permissions boundary, or resource-based policy is involved. When the developer tries to read an object from that bucket, what happens?

  1. The allow policy wins because it was attached to the user first
  2. The request is denied, because an explicit Deny in any applicable policy always overrides an Allow
  3. AWS grants the request because at least one policy contains an Allow statement for the action
  4. The IAM console prompts the developer to pick which of the two policies should apply
AWS SAA-C03 · IAM & Security · Card 002/024 easy

A company wants an IAM role in Account A to be able to read objects from an S3 bucket owned by Account B, without the security team in Account B creating any duplicate IAM user or role. Which approach achieves this directly?

  1. Attach an identity-based policy to the Account A role granting s3:GetObject on the bucket's ARN, since that alone is sufficient for cross-account resource access
  2. Ask Account B to create an IAM user with the same name as the Account A role
  3. Enable S3 Transfer Acceleration on the bucket so cross-account requests bypass IAM checks
  4. Attach a bucket policy (a resource-based policy) on the Account B bucket that names the Account A role's ARN as an allowed principal
AWS SAA-C03 · IAM & Security · Card 003/024 easy

An application running on an EC2 instance needs to call AWS APIs. The security team requires that no long-lived access keys ever be stored on the instance. Which approach satisfies this requirement?

  1. Attach an IAM role to the EC2 instance through an instance profile, so the application retrieves short-lived credentials automatically from the instance metadata service
  2. Create an IAM user, generate an access key pair, and embed the keys in the instance's user data script
  3. Create an IAM user and have a developer manually enter its access key ID and secret access key into the application's configuration file
  4. Store the AWS account root user's access keys in an environment variable on the instance
AWS SAA-C03 · IAM & Security · Card 004/024 medium

A platform team lets application teams create their own IAM roles for their workloads, but wants a guarantee that none of those self-created roles can ever be granted IAM administrative permissions or access to one specific sensitive S3 bucket, no matter what identity-based policy an application team attaches later. Which IAM feature is designed for this?

  1. A service control policy attached directly to each application team's individual IAM role
  2. An IAM policy simulator report that a reviewer runs manually before every deployment
  3. A permissions boundary attached to the roles that caps their maximum possible permissions regardless of what identity-based policies are attached afterward
  4. A resource-based policy added to every future resource those roles might ever need to access
AWS SAA-C03 · IAM & Security · Card 005/024 medium

A company manages many AWS accounts under AWS Organizations. The security team wants one guardrail, applied at the organizational unit level, that prevents every IAM principal in every member account under that OU from ever disabling AWS CloudTrail — even a principal that has full administrator permissions from a local identity-based policy. Which control should they use?

  1. An IAM permissions boundary applied individually to every administrator role in every member account
  2. A service control policy attached to the OU that explicitly denies the CloudTrail-disabling actions for every principal in every account under it
  3. A resource-based policy attached directly to the CloudTrail trail
  4. An IAM group in the organization's management account that contains all administrators
AWS SAA-C03 · IAM & Security · Card 006/024 medium

An engineer in Account A needs temporary access to resources in Account B for a scheduled maintenance task. The security team wants the access to expire automatically after a short session rather than persist afterward. Which mechanism achieves this?

  1. Create a permanent IAM user in Account B and share its access keys with the engineer for the task
  2. Grant the engineer's Account A IAM user a resource-based policy directly on every resource in Account B
  3. Add the engineer's Account A user ARN to an IAM group inside Account B
  4. Have the engineer call AWS STS to assume an IAM role in Account B whose trust policy permits Account A, receiving temporary credentials that expire automatically
AWS SAA-C03 · IAM & Security · Card 007/024 easy

A company wants employees to sign in once using their existing corporate directory credentials and then access multiple AWS accounts, without AWS Organizations creating a separate IAM user in each individual account. Which AWS service is designed for this centralized workforce access pattern?

  1. AWS IAM Identity Center (the successor to AWS SSO), federating a central identity source to permission sets across multiple accounts
  2. Creating an identical IAM user with the same password in every member account
  3. Amazon Cognito user pools attached to each account's root user
  4. AWS Certificate Manager, issuing a shared client certificate to every employee
AWS SAA-C03 · IAM & Security · Card 008/024 easy

A security team wants an IAM policy statement that allows a sensitive action only when the calling principal authenticated with multi-factor authentication during the current session. Which policy element accomplishes this?

  1. A resource-based policy on the target service that checks the caller's password history
  2. A permissions boundary set to a built-in "MFA-only" mode
  3. A Condition element that tests the aws:MultiFactorAuthPresent context key against true
  4. A separate IAM group named "MFA-users" that AWS automatically enforces at the API layer
AWS SAA-C03 · IAM & Security · Card 009/024 hard

An application encrypts large files by calling AWS KMS's GenerateDataKey operation to obtain a plaintext data key and its KMS-encrypted copy, encrypts the file locally with the plaintext data key, discards the plaintext key from memory, and stores only the encrypted copy of the data key alongside the file. What is this pattern called, and why does KMS support it?

  1. Client-side master key rotation, used because KMS cannot rotate customer master keys automatically
  2. Envelope encryption, used because AWS KMS's Encrypt and Decrypt API calls have a payload size limit unsuited to large data, so the bulk data is encrypted locally with a data key while only that small data key is protected directly by KMS
  3. Field-level encryption, used because KMS can only encrypt structured JSON fields, not arbitrary binary files
  4. Envelope encryption, used specifically to avoid ever calling the KMS API during encryption operations
AWS SAA-C03 · IAM & Security · Card 010/024 hard

An IAM role in Account A has an identity-based policy that allows kms:Decrypt on a specific customer managed KMS key that lives in Account B, naming the correct key ARN. The role attempts to decrypt data with that key and is denied. What is the most likely missing piece?

  1. Identity-based policies are ignored entirely whenever the target KMS key belongs to a different account
  2. The role's identity-based policy must instead be rewritten as a service control policy
  3. KMS keys do not support cross-account access under any configuration
  4. The KMS key's own key policy in Account B must also explicitly allow the Account A role to use the key; for KMS, both the identity-based policy and the key policy must authorize the action
AWS SAA-C03 · IAM & Security · Card 011/024 medium

A team stores a database password that must rotate automatically on a schedule, with AWS managing the rotation workflow rather than the team building their own scheduling logic. Separately, they store a handful of static configuration values that never change and need no rotation at all. Which pairing of AWS services best fits these two needs respectively?

  1. AWS Secrets Manager for the password, using its built-in rotation support; AWS Systems Manager Parameter Store SecureString parameters for the static configuration values
  2. AWS Systems Manager Parameter Store for the password, because it offers built-in automatic rotation for any secret type; AWS Secrets Manager for the static values
  3. Amazon Cognito for the password rotation; AWS KMS for storing the static configuration values
  4. AWS Certificate Manager for the password; Amazon S3 Object Lock for the static configuration values
AWS SAA-C03 · IAM & Security · Card 012/024 easy

A public-facing web application behind an Application Load Balancer is being probed with SQL injection attempts inside request bodies. The team wants to inspect and block malicious requests based on their HTTP content before they reach the application, without changing application code. Which service should they attach to the load balancer?

  1. Amazon GuardDuty, attached directly to the ALB to inspect request payloads
  2. AWS Shield Advanced, configured with a custom Layer 7 payload-inspection rule
  3. AWS WAF, associated with the ALB through a web ACL containing a rule that matches SQL injection patterns
  4. Security groups on the ALB, adding an inbound rule that denies traffic containing SQL keywords
AWS SAA-C03 · IAM & Security · Card 013/024 medium

A security team wants continuous, automated detection of suspicious activity, such as unusual API calls or communication with known-malicious IP addresses, using existing VPC Flow Logs, DNS query logs, and CloudTrail events, without deploying any agent on their instances. Which service fits this need?

  1. AWS Config, configured with custom rules that scan flow logs hourly
  2. Amazon GuardDuty, which continuously analyzes VPC Flow Logs, DNS query logs, and CloudTrail events using threat intelligence to generate findings without requiring any agent installation
  3. AWS Systems Manager Inventory, which lists installed software on managed instances
  4. Amazon Inspector, whose vulnerability scans are focused on detecting network intrusions rather than software vulnerabilities
AWS SAA-C03 · IAM & Security · Card 014/024 hard

A company running a website behind CloudFront wants protection against common network and transport layer DDoS attacks automatically included at no extra charge. Separately, its finance team wants a paid service that provides DDoS-related cost protection against scaling charges and access to 24/7 specialist support during a large, sustained attack. Which pairing correctly matches AWS's DDoS-related offerings to these two needs respectively?

  1. AWS Shield Standard automatically protects all AWS customers at no extra charge against common layer 3/4 DDoS attacks; AWS Shield Advanced is the paid tier that adds DDoS cost protection and access to the AWS DDoS Response Team
  2. AWS Shield Advanced is included automatically for every AWS customer; AWS Shield Standard is the paid upgrade that adds the DDoS Response Team
  3. AWS WAF provides the automatic free protection; AWS Shield Standard is the paid tier that adds cost protection
  4. Amazon CloudFront has no DDoS protection at all unless AWS Shield is purchased and separately enabled on every distribution
AWS SAA-C03 · IAM & Security · Card 015/024 medium

A security team manages many AWS accounts under AWS Organizations and wants to identify, across every account, each S3 bucket, IAM role, and KMS key whose resource-based policy grants access to a principal outside their own accounts, without manually inspecting every resource policy by hand. Which service is designed for this?

  1. Amazon GuardDuty, which uses machine learning to detect anomalous account and network behavior from VPC Flow Logs, DNS query logs, and CloudTrail events
  2. AWS Config, which records configuration changes for supported resources over time and evaluates them against compliance rules
  3. IAM Access Analyzer, which defines a zone of trust for an account or organization and uses automated reasoning on resource-based policies to generate a finding whenever a resource is shared with a principal outside that zone
  4. AWS Trusted Advisor, which checks accounts against a fixed set of cost, performance, and security best-practice checks
AWS SAA-C03 · IAM & Security · Card 016/024 easy

A compliance team wants continuous visibility into whether every EBS volume in an account remains encrypted, with automatic flagging the moment a volume becomes non-compliant, plus a historical record of every configuration change made to that volume over time. Which service should they use?

  1. AWS Config, which continuously records configuration changes for supported resources and can evaluate them against managed or custom rules such as one that checks for encrypted volumes
  2. AWS CloudTrail, which logs the history of API calls made by users, roles, and services in the account
  3. Amazon Inspector, which scans EC2 instances and container images for known software vulnerabilities
  4. AWS Trusted Advisor, which provides a fixed set of best-practice checks refreshed on a set schedule
AWS SAA-C03 · IAM & Security · Card 017/024 easy

A company stores millions of objects in Amazon S3 and wants to automatically discover which objects contain sensitive data, such as national ID numbers or credit card numbers, using machine learning and pattern matching, and to be alerted if a bucket holding that data becomes publicly accessible. Which service fits this need?

  1. Amazon Inspector, which scans workloads for known software vulnerabilities and unintended network reachability
  2. Amazon Macie, which uses machine learning and pattern matching to discover sensitive data such as personally identifiable information in S3 objects and monitors buckets for public-access and other security risks
  3. AWS Config, which evaluates resource configurations against compliance rules
  4. Amazon GuardDuty, which detects malicious or anomalous account and network activity from log analysis
AWS SAA-C03 · IAM & Security · Card 018/024 medium

A security team already runs Amazon GuardDuty, Amazon Macie, and Amazon Inspector across their accounts and now wants one dashboard that ingests and normalizes findings from all three, and separately checks their environment against a security industry standard such as the CIS AWS Foundations Benchmark, prioritizing everything in a single place. Which service should they add?

  1. AWS Config, configured with enough custom rules to independently reproduce each of these checks
  2. AWS Systems Manager, to patch instances and inspect general operational configuration
  3. Amazon Detective, to visualize the likely root cause of one already-known security finding
  4. AWS Security Hub, which ingests and normalizes findings from services such as GuardDuty, Macie, and Inspector into a standard format, and separately runs its own checks against security standards such as the CIS AWS Foundations Benchmark
AWS SAA-C03 · IAM & Security · Card 019/024 hard

A team enables automatic key rotation, using the default settings, on a symmetric customer managed KMS key whose key material AWS KMS generated. They also have a separate asymmetric customer managed KMS key that they would like to rotate on a similar automatic schedule. What should they expect?

  1. The symmetric key rotates automatically every 365 days unless a custom rotation period between 90 and 2560 days is specified; the asymmetric key is not eligible for automatic or on-demand rotation and must instead be rotated manually by creating a new key and updating references to it
  2. Both keys rotate automatically every 365 days once automatic rotation is enabled, because AWS KMS treats every customer managed key type identically for rotation purposes
  3. Neither key can ever have its key material rotated after creation; the only way to rotate is to close the account and open a new one
  4. The asymmetric key rotates automatically every 90 days by default, while the symmetric key requires manual rotation because it holds the material actually used to encrypt data
AWS SAA-C03 · IAM & Security · Card 020/024 medium

A team requests three ACM public certificates: one attached to a CloudFront distribution and validated using DNS validation, one requested through ACM using email validation but never attached to any AWS resource, and one imported into ACM from a third-party certificate authority. Which of these will renew before expiry without any manual action from the team?

  1. All three, because ACM automatically manages renewal for every certificate in its inventory regardless of validation method or usage
  2. Only the imported third-party certificate, because ACM tracks externally issued certificates most closely for expiry
  3. Only the certificate attached to the CloudFront distribution: it renews automatically because it is DNS-validated and currently in use by an AWS service, while the email-validated certificate needs the domain owner to click a renewal link and the imported certificate is never eligible for managed renewal at all
  4. None of the three, because ACM never renews any certificate automatically and always requires submitting a brand-new certificate request
AWS SAA-C03 · IAM & Security · Card 021/024 easy

A newly created AWS account's root user currently has no MFA device configured and an active access key that a script uses to run a daily automated task. Which change best aligns with AWS root user security best practices?

  1. Keep using the root access key for the daily script, since only the root user can guarantee sufficient permissions, and add a second root access key for redundancy
  2. Enable MFA on the root user, delete the root user's access keys, and move the daily automated task to an IAM role or IAM user that has only the permissions it needs
  3. Disable MFA entirely on every user in the account including root, since MFA devices are a common cause of account lockouts
  4. Create several additional root users, one per team, so that no single team depends on the same root credentials
AWS SAA-C03 · IAM & Security · Card 022/024 hard

An enterprise already runs its own SAML 2.0-compliant identity provider for internal employee logins and wants employees to obtain temporary AWS credentials to access resources in a single AWS account directly, by federating their existing identity provider straight into IAM, without adopting AWS's own managed workforce SSO service and without creating any IAM user for any employee. Which approach fits?

  1. Configure IAM Identity Center as the enterprise's identity provider, since it is the only supported way to federate any external identity provider with AWS
  2. Create an IAM user for every employee and have the identity provider place a long-lived AWS access key into each user's browser session
  3. Use AWS Directory Service to fully replace the enterprise's existing identity provider, since IAM cannot trust an external SAML provider directly
  4. Create a SAML identity provider entity in IAM that trusts the enterprise's identity provider, then create an IAM role whose trust policy allows that SAML provider to call AssumeRoleWithSAML, so authenticated employees receive temporary credentials scoped to that role without any IAM user ever being created
AWS SAA-C03 · IAM & Security · Card 023/024 easy

A mobile app lets users browse public content without signing in, but if a user signs in through a supported social identity provider, the app should let that user upload files directly to an S3 bucket using temporary AWS credentials scoped to their identity, without the app's backend ever handling long-lived AWS credentials. Which service is designed for this?

  1. IAM Identity Center, which provides workforce single sign-on to multiple AWS accounts and business applications
  2. AWS STS AssumeRole called directly from the mobile app using a long-lived IAM user access key embedded in the app
  3. Amazon Cognito identity pools, which issue temporary AWS credentials scoped to an IAM role for both unauthenticated guest users and users authenticated through a supported identity provider
  4. AWS Directory Service, which provides a managed Microsoft Active Directory for domain-joined workloads
AWS SAA-C03 · IAM & Security · Card 024/024 easy

A security team wants an S3 bucket policy with two statements: one that denies any request not made over HTTPS, and a separate one that denies any request originating outside the company's known corporate IP range, regardless of which IAM identity makes the request. Which condition keys should these two statements use, respectively?

  1. aws:MultiFactorAuthPresent for the HTTPS requirement, and aws:PrincipalOrgID for the IP-range requirement
  2. aws:SecureTransport for the HTTPS requirement, and aws:SourceIp for the IP-range requirement
  3. aws:SourceIp for the HTTPS requirement, and aws:SecureTransport for the IP-range requirement
  4. aws:CurrentTime for the HTTPS requirement, and aws:UserAgent for the IP-range requirement