53 practice questions for Domain 1 of the AWS Certified Solutions Architect - Associate (SAA-C03) exam, which makes up 30% of its scored content. Your answers count towards one score and one timer for the whole exam.
Domain 1: Design Secure Architectures
1. An organization uses AWS Organizations. Security requires that no member account can stop or delete AWS CloudTrail trails, even by an account administrator. Which solution meets these requirements?
Answer and explanation
Answer: C. A service control policy caps the permissions available in a member account and cannot be removed from inside that account. An IAM deny attached to administrators can be detached by those same administrators. Permissions boundaries do not apply to the root user and are set within the account. A Config rule remediates after the trail has already stopped, leaving a gap in the record.
2. A mobile application must let users sign in with an existing corporate SAML identity provider and then call AWS APIs with credentials scoped to a specific role. Which solution meets these requirements?
Answer and explanation
Answer: B. Federation exchanges the SAML assertion for short-lived STS credentials scoped to a role, so no long-term secret reaches the device and access expires automatically. An IAM user per mobile user does not scale and still requires distributing long-term keys. A shared key embedded in a distributed application can be extracted from it. Root credentials must never be used programmatically.
3. A security investigator must read the contents of one Amazon S3 prefix during an investigation but must not be able to modify or delete any object. Which solution meets these requirements?
Answer and explanation
Answer: C. Granting only the read action on the specific prefix permits inspection with no mutation capability. Granting s3:* includes PutObject and DeleteObject. Bucket ownership confers administrative control. A public read policy exposes the prefix to everyone on the internet.
4. A company must let users authenticate to an application with credentials from an existing on-premises Active Directory. Directory data must not be replicated into AWS. Which solution meets these requirements?
Answer and explanation
Answer: D. AD Connector proxies authentication requests to the existing directory and stores no directory data in AWS. A managed Microsoft AD with a trust creates a directory in AWS, and a trust relationship still involves an AWS-resident directory. Simple AD with synchronization copies user data into AWS. Importing users into Cognito duplicates the identity store.
5. A security team must be notified when any resource policy in the organization grants access to a principal outside the organization. Which solution meets these requirements?
Answer and explanation
Answer: D. Access Analyzer evaluates resource and trust policies for access granted outside the defined zone of trust, and setting the organization as that zone reports only genuinely external access. Using the account as the zone of trust would report every legitimate cross-account grant within the organization as a finding. A Config rule evaluates configuration against defined conditions rather than performing policy reachability analysis. GuardDuty detects threat activity rather than enumerating policy grants.
6. An application running on servers in an on-premises data center must call AWS APIs. No long-term AWS credentials may be stored on those servers. Which solution meets these requirements?
Answer and explanation
Answer: B. Roles Anywhere exchanges a certificate issued by a registered certificate authority for temporary credentials, so no long-term secret exists on the server. Access keys in a configuration file are exactly the long-term credential being avoided, and distributing them through configuration management spreads the same secret. The instance metadata service is reachable only from within an EC2 instance.
7. A resource policy must grant access to any principal in the company's AWS Organization, and must remain correct as accounts are added and removed. Which solution meets these requirements?
Answer and explanation
Answer: C. aws:PrincipalOrgID matches any principal in the specified organization, so the policy needs no change as membership varies. A list of account IDs must be maintained whenever an account joins or leaves. A VPC list restricts by network origin rather than organization membership and requires similar maintenance. A principal ARN wildcard does not express organization membership and would match roles in accounts outside it.
8. An application must generate time-limited access to individual objects in Amazon S3 for authenticated users, and that access must expire automatically. Which solution meets these requirements?
Answer and explanation
Answer: B. A presigned URL carries an explicit expiry and stops working when either that expiry or the signing credentials' lifetime is reached, which is why the signing credentials must outlive the intended window. Root access keys should not exist and must never be used to sign requests. Adding and removing a bucket policy is manual and affects every object the statement covers. Managing an IAM policy per access period does not scale to individual objects.
9. A company runs an application on Amazon EC2 instances in private subnets. The application must read objects from an Amazon S3 bucket. Company policy prohibits any route from the private subnets to the internet, including through NAT devices. Which solution meets these requirements?
Answer and explanation
Answer: C. A gateway endpoint adds a prefix list route for Amazon S3 that keeps traffic on the AWS network, costs nothing, and needs no internet path. An interface endpoint reaches S3 through PrivateLink but is not added to a route table and carries an hourly charge, so the described configuration is wrong. A NAT gateway is a route to the internet, which policy forbids. An internet gateway route converts the subnets into public subnets.
10. A web tier in public subnets must accept HTTPS from the internet. An application tier in private subnets must accept traffic only from the web tier, and the fleet size changes throughout the day. Which solution meets these requirements?
Answer and explanation
Answer: A. Referencing the web tier security group matches by group membership, so the rule stays correct as instances launch and terminate. A CIDR-based rule permits anything in those subnets, not only the web tier, and needs maintenance if addressing changes. Network ACLs filter by address and cannot reference a security group. Allowing 0.0.0.0/0 and relying on a stateless ACL inverts least privilege.
11. An Amazon RDS database in private subnets must be reachable by an application in a VPC owned by another AWS account. The database must not be reachable from the internet. Which combination of steps meets these requirements? (Select TWO.)
Answer and explanation
Answer: B, E. Peering plus routes on both sides establishes private connectivity, and the security group must then permit the peer CIDR. Moving the database to a public subnet exposes it regardless of the security group. An internet gateway creates the exposure the requirement forbids. A NAT gateway provides outbound internet access and does nothing for inbound traffic from a peer.
12. Instances in private subnets must call a partner API over the internet. The partner allows traffic only from a small, fixed set of public IP addresses. Which solution meets these requirements?
Answer and explanation
Answer: C. A NAT gateway presents its Elastic IP as the source address for everything behind it, which is a stable set of addresses for an allow-list. Per-instance Elastic IPs change as instances are replaced and would require constant allow-list updates. A VPC CIDR is a private range that the partner never observes. PrivateLink applies to services published on AWS and is not available for an arbitrary external API.
13. An application on Amazon EC2 in private subnets must read from one Amazon DynamoDB table. Traffic must not traverse the internet, and the instances must not be able to reach any other table. Which combination of steps meets these requirements? (Select TWO.)
Answer and explanation
Answer: C, E. A gateway endpoint keeps DynamoDB traffic on the AWS network, and a role scoped to one table ARN prevents access to any other. A NAT gateway routes the traffic over the internet unnecessarily. Granting dynamodb:* on all resources defeats the isolation requirement. DynamoDB tables do not take bucket policies.
14. An Amazon API Gateway REST API must remain publicly routable but must accept requests only from the company's office network. Which solution meets these requirements?
Answer and explanation
Answer: C. A resource policy with a source IP condition rejects requests from other networks at the API while the endpoint remains public. API Gateway endpoints do not take security groups. Converting to a private API removes the public routability the requirement preserves. An API key identifies a caller for usage plans and can be used from anywhere.
15. A company must expose one internal service to dozens of consumer VPCs in other accounts. Consumers must reach that service only, and no routed path may exist between the networks. Which solution meets these requirements?
Answer and explanation
Answer: D. PrivateLink exposes a single service through interface endpoints in consumer VPCs, so consumers reach that service and nothing else and no routed path exists. Peering and transit gateway both create general routed connectivity between the networks. A public load balancer exposes the service to the internet and IP allow-lists do not authenticate the caller.
16. A public web application is subject to credential stuffing attacks against its sign-in endpoint. Which solution provides the MOST effective mitigation?
Answer and explanation
Answer: D. The account takeover prevention rule group inspects sign-in attempts for stolen-credential patterns, and a rate-based rule throttles high-volume attempts, which together address the attack. A rate-based rule alone at a high threshold misses low-and-slow credential stuffing. A security group permitting port 443 allows exactly the traffic the attack uses. Shield Standard mitigates network and transport layer DDoS rather than application-layer credential abuse.
17. Engineers require interactive shell access to Amazon EC2 instances in private subnets. No inbound ports may be opened, no bastion host may be deployed, and every session must be recorded. Which solution meets these requirements?
Answer and explanation
Answer: B. Session Manager opens a shell through the SSM agent using IAM permissions with no inbound ports or bastion, and session logging records the full transcript. Session Manager without logging fails the recording requirement. A bastion is explicitly excluded and opens an inbound port. An Instance Connect Endpoint avoids the bastion but does not by itself produce a session transcript.
18. Traffic between clients and an Application Load Balancer is encrypted. Compliance requires that traffic between the load balancer and its Amazon EC2 targets is also encrypted. Which combination of steps meets these requirements? (Select TWO.)
Answer and explanation
Answer: B, D. End-to-end encryption requires the target group to use HTTPS and the targets themselves to terminate TLS with a certificate installed. EBS encryption protects data at rest rather than in transit. A security group restricts which port is reachable without encrypting what flows over it. Access logging records requests and does not affect the connection.
19. An application on Amazon EC2 must read a database password at run time. The password must rotate every 30 days without any change to application code or configuration. Which solution meets these requirements with the LEAST operational overhead?
Answer and explanation
Answer: C. Secrets Manager rotates the credential on a schedule with a rotation function and serves it to the instance through its role, so nothing in the application changes. A String parameter is neither encrypted nor rotated automatically, and SecureString would still lack native rotation. Replacing the launch template requires new instances on every rotation. An encrypted S3 object protects the value at rest but provides no rotation.
20. A company must ensure that every object written to an Amazon S3 bucket is encrypted with one specific AWS KMS key. Uploads that request a different key or no encryption must be rejected. Which solution meets these requirements?
Answer and explanation
Answer: B. A bucket policy condition on the requested key ARN rejects the PutObject call itself, which is what the requirement demands. Default encryption applies the key when the request omits one but does not reject a request naming a different key. Block Public Access governs public exposure and has no bearing on key selection. Lifecycle rules transition or expire objects and cannot re-encrypt them.
21. A company must encrypt an Amazon EFS file system at rest and encrypt traffic between Amazon EC2 instances and the file system. Which combination of steps meets these requirements? (Select TWO.)
Answer and explanation
Answer: A, B. EFS encryption at rest must be selected at creation and cannot be added later, and in-transit encryption is opted into by mounting with TLS through the mount helper. Enabling encryption at rest afterwards is not possible. Subnet placement controls reachability rather than encryption. A mount policy is authorization rather than confidentiality of the data.
22. An application must verify that an object retrieved from Amazon S3 is byte-for-byte identical to the object that was uploaded. Which solution meets these requirements?
Answer and explanation
Answer: B. S3 stores an additional checksum recorded at upload, and recomputing it on retrieval detects any alteration to the bytes. A version ID identifies which version was returned without attesting to its contents. Object size in an access log would not detect a change that preserves length. A restrictive bucket policy limits who can write and proves nothing about integrity.
23. A company stores customer documents in Amazon S3. A document deleted by a user must remain recoverable for 30 days and must then be removed permanently. Which solution meets these requirements?
Answer and explanation
Answer: D. With versioning a delete places a marker and retains the prior version, and a noncurrent-version expiry removes it at exactly 30 days. Expiring current versions deletes live documents rather than deleted ones. Object Lock prevents deletion entirely, which conflicts with letting users delete. Replication can propagate a delete marker and addresses regional resilience rather than user error.
24. Thousands of teams share one Amazon S3 bucket, each with its own prefix and distinct permissions. The bucket policy has reached its size limit. Which solution meets these requirements?
Answer and explanation
Answer: B. Access Points decompose a monolithic bucket policy into a named endpoint and policy per team, which is the documented answer to a bucket policy hitting its size limit. A bucket per team multiplies management and can reach the account bucket quota. Consolidating statements postpones the limit without removing it. Role policies help but leave the resource policy problem in place when cross-account or public access must be controlled at the bucket.
25. A company must ensure that every new Amazon EBS volume and snapshot in an account is encrypted, without depending on users selecting the option. Which solution meets these requirements?
Answer and explanation
Answer: B. Encryption by default causes every new volume and snapshot to be encrypted regardless of the request, which prevents the non-compliant state. A Config rule detects the volume after it exists and cannot retroactively encrypt it in place. An IAM deny works for principals it is attached to but must be applied everywhere and can be bypassed by other identities. A tag asserts intent without encrypting anything.
26. A task running on Amazon ECS with the Fargate launch type must retrieve one secret from AWS Secrets Manager. The secret is encrypted with a customer managed AWS KMS key. Which combination of steps meets these requirements? (Select TWO.)
Answer and explanation
Answer: A, C. A task role scoped to the secret ARN grants the minimum needed, and decrypting a secret protected by a customer managed key also requires kms:Decrypt in that key's policy. A plaintext environment variable exposes the secret to anyone who can describe the task definition. Granting secretsmanager:* on all secrets is not least privilege. Fargate exposes no customer-managed host, so there is no instance profile to attach.
27. Objects in an Amazon S3 bucket must remain readable only to principals that also hold permission on a specific encryption key, so that object-level permissions alone are insufficient. Which solution meets these requirements?
Answer and explanation
Answer: D. With SSE-KMS the object cannot be decrypted without kms:Decrypt on the key, so the key policy becomes a second independent gate beyond object permissions. S3 managed keys are applied transparently and provide no separate permission check. Block Public Access prevents public exposure but authenticated principals with object permissions still read the data. Versioning preserves object history.
28. A compliance archive in Amazon S3 must be provably unaltered for seven years, and no principal including the account root user may delete or overwrite an object version during that period. Which combination of steps meets these requirements? (Select TWO.)
Answer and explanation
Answer: A, E. Compliance mode blocks deletion and overwrite by every principal including root until retention expires, and a recorded checksum lets the contents be verified independently. Governance mode can be bypassed by principals holding the bypass permission. A bucket policy can be modified by an administrator. MFA Delete adds an authentication step rather than creating immutability.
29. A company must guarantee that no Amazon S3 bucket in an account can be made publicly accessible, including buckets created in the future. Which solution meets these requirements?
Answer and explanation
Answer: A. Account-level Block Public Access overrides any bucket policy or ACL that would grant public access and applies to buckets created later. Enabling it per bucket leaves future buckets uncovered. A bucket policy denying policy changes can itself be replaced by an administrator. A Config rule remediates after the bucket has already been exposed.
30. An application on Amazon EC2 must access an S3 bucket in a different account. Which solution meets these requirements?
Answer and explanation
Answer: D. An instance role permitted by the other account's bucket policy provides cross-account access with temporary credentials. Stored keys are a long-term secret. A public bucket exposes the data. Copying duplicates storage and drifts.
31. A company must allow employees to sign in to the AWS Management Console using their existing corporate credentials. Which solution meets these requirements?
Answer and explanation
Answer: C. IAM Identity Center federates the corporate provider for console access across accounts. Per-employee IAM users duplicate the directory. A shared user destroys attribution. Cognito serves application end users rather than console access.
32. An IAM policy must permit an action only when the request comes from a specific VPC endpoint. Which element is required?
Answer and explanation
Answer: C. The aws:sourceVpce condition key restricts requests to a named endpoint. Endpoints are not resources or principals in a policy statement for this purpose. Endpoint service actions govern endpoint management.
33. A solution must grant a mobile application's users temporary AWS credentials scoped to their own data. Which solution meets these requirements?
Answer and explanation
Answer: B. Cognito identity pools issue temporary credentials whose policy can scope to the caller's identity. Embedded keys are extractable from the application. An IAM user per mobile user does not scale. A shared role with full access does not scope per user.
34. An application's database credentials must be rotated automatically and retrieved by the application at run time. Which solution meets these requirements?
Answer and explanation
Answer: A. Secrets Manager rotates on a schedule and serves the current value at run time. A String parameter is neither encrypted nor rotated. Environment variables and packaged files require redeployment to change.
35. An Amazon EC2 instance in a private subnet must download operating system updates from the internet without being reachable from it. Which solution meets these requirements?
Answer and explanation
Answer: B. A NAT gateway permits outbound-initiated connections while blocking inbound attempts. An internet gateway route makes the subnet public. An Elastic IP address makes the instance reachable. A public subnet exposes the instance regardless of the security group's intent.
36. A web application must be protected from SQL injection attempts. Which solution meets these requirements?
Answer and explanation
Answer: A. WAF managed rule groups inspect requests for injection patterns. A port restriction permits exactly the traffic the attack uses. Shield Standard mitigates network and transport layer DDoS. Flow Logs record traffic metadata.
37. Instances in an Auto Scaling group must be permitted to reach a database, and the group's instances change frequently. Which security group configuration is appropriate?
Answer and explanation
Answer: D. Security group referencing remains correct as instances are replaced. IP lists require updating on every change. The VPC CIDR permits every resource in the VPC. Permitting all traffic removes the network control.
38. Objects in an Amazon S3 bucket must be encrypted, and the encryption key's use must be auditable. Which solution meets these requirements?
Answer and explanation
Answer: B. A customer managed key records every cryptographic operation in CloudTrail and exposes a key policy. S3 managed keys provide no key usage trail. Versioning preserves history. Block Public Access prevents public exposure.
39. Data on an Amazon EBS volume attached to an existing unencrypted instance must be encrypted. Which solution meets these requirements?
Answer and explanation
Answer: C. An existing unencrypted volume is encrypted by snapshotting, copying with encryption, and creating a new volume. Encryption cannot be enabled in place. Encryption by default applies to newly created volumes. Restoring to the same volume does not encrypt it.
40. A company must retain S3 objects so that no user can delete them before a retention period expires. Which solution meets these requirements?
Answer and explanation
Answer: C. Compliance mode prevents deletion by every principal including the root user until retention expires. A bucket policy can be modified. MFA Delete adds an authentication step. A storage class does not confer immutability.
41. Traffic between an Application Load Balancer and its EC2 targets must be encrypted. Which solution meets these requirements?
Answer and explanation
Answer: C. Encrypting the backend connection requires the target group to use HTTPS with certificates on the targets. An HTTPS listener alone encrypts only the client connection. At-rest encryption protects stored data. Zone placement does not encrypt.
42. An application must assume different roles depending on which customer's data it is processing. Which solution meets these requirements?
Answer and explanation
Answer: D. A per-customer role assumption with a session policy scopes access to the tenant being served. A single broad role permits cross-tenant access, IAM users per customer do not scale, and administrator access removes the control.
43. An IAM policy must permit an action only when the caller has authenticated with multi-factor authentication. Which element is required?
Answer and explanation
Answer: A. aws:MultiFactorAuthPresent tests whether multi-factor authentication was used. SecureTransport tests TLS, PrincipalOrgID tests organization membership, and SourceIp tests network origin.
44. A solution must grant an on-premises application access to AWS without long-term credentials. Which solution meets these requirements?
Answer and explanation
Answer: A. Roles Anywhere exchanges a registered certificate for temporary credentials. Stored keys are the long-term credential being avoided, instance profile credentials are not transferable, and root credentials must never be used.
45. An organization must prevent any principal outside the organization from assuming its roles. Which solution meets these requirements?
Answer and explanation
Answer: D. aws:PrincipalOrgID restricts assumption to principals in the organization. Source IP restricts network origin, removing all cross-account trust blocks legitimate access, and multi-factor authentication does not restrict which account the principal belongs to.
46. A federated user must receive permissions determined by a group in the corporate directory. Which solution meets these requirements?
Answer and explanation
Answer: C. Permission sets mapped to directory groups make membership determine access. IAM users duplicate the directory, a uniform role ignores group membership, and manual assignment does not scale.
47. An application must be prevented from using credentials outside a specific VPC. Which solution meets these requirements?
Answer and explanation
Answer: B. A VPC condition restricts where the credentials may be used. Subnet placement and security groups control reachability, and session duration limits time rather than location.
48. Objects uploaded to Amazon S3 must be encrypted with a key that AWS cannot access. Which solution meets these requirements?
Answer and explanation
Answer: D. Client-side encryption with an externally held key means AWS never has the plaintext or the key. All server-side options involve AWS performing the encryption.
49. An RDS database's automated backups must be encrypted. Which consideration applies?
Answer and explanation
Answer: B. Backups inherit the instance's encryption state, which is set at creation. They cannot be encrypted independently or retroactively, and are not encrypted by default on an unencrypted instance.
50. Data on an Amazon EFS file system must be encrypted in transit between instances and the file system. Which configuration is required?
Answer and explanation
Answer: D. The TLS mount option encrypts traffic in transit. At-rest encryption protects stored data, and subnet placement and security groups control reachability.
51. An organization must discover which S3 buckets contain personally identifiable information. Which solution meets these requirements?
Answer and explanation
Answer: D. Macie classifies stored content against managed and custom identifiers. A crawler infers schema, access logging records requests, and Config evaluates configuration.
52. A DynamoDB table's data must be encrypted with a key the organization controls and audits. Which configuration is appropriate?
Answer and explanation
Answer: B. A customer managed key provides an author-controlled key policy and CloudTrail records of its use. Default encryption uses an AWS owned key, application-side encryption prevents querying on those attributes, and point-in-time recovery is a backup feature.
53. An organization must ensure that snapshots shared with another account remain encrypted. Which configuration is required?
Answer and explanation
Answer: D. Sharing an encrypted snapshot requires the recipient to have permission on the key. Unencrypted sharing loses the protection, copying does not transfer permission, and public snapshots cannot be encrypted with a customer managed key.