Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam AWS Certified Solutions Architect - Associate SAA-C03 All Questions

View all questions & answers for the AWS Certified Solutions Architect - Associate SAA-C03 exam

Exam AWS Certified Solutions Architect - Associate SAA-C03 topic 1 question 751 discussion

A solutions architect is designing an AWS Identity and Access Management (IAM) authorization model for a company's AWS account. The company has designated five specific employees to have full access to AWS services and resources in the AWS account.

The solutions architect has created an IAM user for each of the five designated employees and has created an IAM user group.

Which solution will meet these requirements?

  • A. Attach the AdministratorAccess resource-based policy to the IAM user group. Place each of the five designated employee IAM users in the IAM user group.
  • B. Attach the SystemAdministrator identity-based policy to the IAM user group. Place each of the five designated employee IAM users in the IAM user group.
  • C. Attach the AdministratorAccess identity-based policy to the IAM user group. Place each of the five designated employee IAM users in the IAM user group.
  • D. Attach the SystemAdministrator resource-based policy to the IAM user group. Place each of the five designated employee IAM users in the IAM user group.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Scheldon
3 months, 3 weeks ago
Selected Answer: C
AnswerC We need identity-based policy and if we will compare System Admin and Administrator Access policy it clear that SysAdmin have is allowing for limited amount of actions, where Admin Access simple allow for all actions. https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_identity-vs-resource.html https://docs.aws.amazon.com/aws-managed-policy/latest/reference/AdministratorAccess.html https://docs.aws.amazon.com/aws-managed-policy/latest/reference/SystemAdministrator.html
upvoted 2 times
...
NSA_Poker
4 months ago
Selected Answer: C
(A & D) eliminated. Resource-based policies are attached to a resource NOT an IAM user, group, or role. (B) eliminated. SystemAdministrator has fewer permissions than AdministratorAccess.
upvoted 3 times
...
Linuslin
5 months ago
Selected Answer: C
The question says "full access to AWS services and resources in the AWS account" and "created an IAM user group." You can see it is identity-based policy, not resource-based.--->A and D are out. SystemAdministrator: Allow 28 of 412 services.--->B is out. AdministratorAccess: Allow 412 of 412 services.--->C is the correct answer. If you are curious about what a policy can allow for, just log in you AWS account and go to IAM-policies to find out.
upvoted 3 times
...
MattBJ
7 months, 3 weeks ago
Selected Answer: C
C is the correct answer
upvoted 1 times
...
osmk
8 months ago
Selected Answer: C
C>>>https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_manage-attach-detach.html
upvoted 2 times
...
osmk
8 months ago
C>>>https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_manage-attach-detach.html
upvoted 2 times
...
Umuntu
8 months, 1 week ago
C looks correct
upvoted 2 times
...
Andy_09
8 months, 1 week ago
Option C
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...