exam questions

Exam AWS Certified Solutions Architect - Associate SAA-C03 All Questions

View all questions & answers for the AWS Certified Solutions Architect - Associate SAA-C03 exam

Exam AWS Certified Solutions Architect - Associate SAA-C03 topic 1 question 476 discussion

A company is expecting rapid growth in the near future. A solutions architect needs to configure existing users and grant permissions to new users on AWS. The solutions architect has decided to create IAM groups. The solutions architect will add the new users to IAM groups based on department.

Which additional action is the MOST secure way to grant permissions to the new users?

  • A. Apply service control policies (SCPs) to manage access permissions
  • B. Create IAM roles that have least privilege permission. Attach the roles to the IAM groups
  • C. Create an IAM policy that grants least privilege permission. Attach the policy to the IAM groups
  • D. Create IAM roles. Associate the roles with a permissions boundary that defines the maximum permissions
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Rob1L
Highly Voted 1 year, 8 months ago
Selected Answer: C
Option B is incorrect because IAM roles are not directly attached to IAM groups.
upvoted 9 times
RoroJ
1 year, 7 months ago
IAM Roles can be attached to IAM Groups: https://docs.aws.amazon.com/directoryservice/latest/admin-guide/assign_role.html
upvoted 4 times
antropaws
1 year, 7 months ago
Read your own link: You can assign an existing IAM role to an AWS Directory Service user or group. Not to IAM groups.
upvoted 10 times
...
...
...
Efren
Highly Voted 1 year, 8 months ago
Selected Answer: C
Agreed with C https://docs.aws.amazon.com/IAM/latest/UserGuide/id_groups_manage_attach-policy.html Attaching a policy to an IAM user group
upvoted 7 times
...
MatAlves
Most Recent 4 months, 1 week ago
Selected Answer: C
"Manage access in AWS by creating policies and attaching them to IAM identities (users, groups of users, or roles) or AWS resources." "An IAM role is an identity within your AWS account that has specific permissions. It's similar to an IAM user, but isn't associated with a specific person." "IAM roles do not have any permanent credentials associated with them and are instead assumed by IAM users, AWS services, or applications that need temporary security credentials to access AWS resources"
upvoted 2 times
MatAlves
4 months, 1 week ago
https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies.html https://docs.aws.amazon.com/IAM/latest/UserGuide/id.html https://blog.awsfundamentals.com/aws-iam-roles-terms-concepts-and-examples
upvoted 2 times
...
...
zinabu
9 months, 2 weeks ago
create role=for resource like EC2 and lambda .... create a Policy =for groups or user access policy for the resources like S3 bucket
upvoted 4 times
...
pentium75
1 year ago
Selected Answer: C
Not A or D because this is not about restricting maximum permissions, it is is about securely granting permissions Not B because IAM roles are not attached to IAM groups. C because IAM policies are attached to IAM groups.
upvoted 5 times
...
potomac
1 year, 2 months ago
Selected Answer: C
A is wrong SCPs are mainly used along with AWS Organizations organizational units (OUs). SCPs do not replace IAM Policies such that they do not provide actual permissions. To perform an action, you would still need to grant appropriate IAM Policy permissions.
upvoted 3 times
...
Guru4Cloud
1 year, 5 months ago
Selected Answer: C
Create an IAM policy that grants least privilege permission. Attach the policy to the IAM groups
upvoted 2 times
...
TariqKipkemei
1 year, 7 months ago
Selected Answer: C
An IAM policy is an object in AWS that, when associated with an identity or resource, defines their permissions. Permissions in the policies determine whether a request is allowed or denied. You manage access in AWS by creating policies and attaching them to IAM identities (users, groups of users, or roles) or AWS resources. So, option B will also work. But Since I can only choose one, C would be it.
upvoted 3 times
...
MrAWSAssociate
1 year, 7 months ago
Selected Answer: C
You can attach up to 10 IAM policy for a 'user group'.
upvoted 2 times
...
antropaws
1 year, 7 months ago
Selected Answer: C
C is the correct one.
upvoted 2 times
...
nosense
1 year, 8 months ago
Selected Answer: B
should be b
upvoted 2 times
imazsyed
1 year, 8 months ago
it should be C
upvoted 4 times
nosense
1 year, 8 months ago
Option C is not as secure as option B because IAM policies are attached to individual users and cannot be used to manage permissions for groups of users.
upvoted 2 times
omoakin
1 year, 8 months ago
IAM Roles manage who has access to your AWS resources, whereas IAM policies control their permissions. A Role with no Policy attached to it won’t have to access any AWS resources. A Policy that is not attached to an IAM role is effectively unused.
upvoted 5 times
Clouddon
1 year, 4 months ago
https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies.html
upvoted 2 times
...
...
...
...
pentium75
1 year ago
IAM roles are not attached to IAM groups. IAM policies are attached to IAM roles, IAM groups or IAM users. IAM roles are used by services.
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago