exam questions

Exam AWS Certified Solutions Architect - Associate SAA-C03 All Questions

View all questions & answers for the AWS Certified Solutions Architect - Associate SAA-C03 exam

Exam AWS Certified Solutions Architect - Associate SAA-C03 topic 1 question 922 discussion

A company needs to grant a team of developers access to the company's AWS resources. The company must maintain a high level of security for the resources.

The company requires an access control solution that will prevent unauthorized access to the sensitive data.

Which solution will meet these requirements?

  • A. Share the IAM user credentials for each development team member with the rest of the team to simplify access management and to streamline development workflows.
  • B. Define IAM roles that have fine-grained permissions based on the principle of least privilege. Assign an IAM role to each developer.
  • C. Create IAM access keys to grant programmatic access to AWS resources. Allow only developers to interact with AWS resources through API calls by using the access keys.
  • D. Create an AWS Cognito user pool. Grant developers access to AWS resources by using the user pool.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
LeonSauveterre
3 months, 3 weeks ago
Selected Answer: B
A - Sharing IAM user credentials is a security risk and violates AWS best practices. B - IAM roles allow for temporary credentials that can be automatically rotated, and that improves security. C - Would work but managing static keys for multiple developers introduces significant operational overhead. D - AWS Cognito is primarily designed for managing end-user authentication (for web or mobile apps or such), not for managing access to AWS resources for developers.
upvoted 1 times
hpirnaj
3 months, 2 weeks ago
it says " team of developers " . they are not in the company's AWS account. how do you want to apply IAM roles without defining users ? I think C is the answer
upvoted 1 times
hpirnaj
3 months, 2 weeks ago
also, roles can not assign to user/group . you need to make a policy from IAM roles first then assign policies to user/group
upvoted 1 times
...
...
...
KennethYY
4 months ago
Selected Answer: D
A is wrong, common sense not security B is wrong, role cannot assign to user/group D is wrong, is designed for authentication and access control for web or mobile app users, not for internal developers accessing AWS resources. so remain C.
upvoted 1 times
...
EllenLiu
4 months ago
Selected Answer: B
AWS Cognito is designed for authentication and access control for web or mobile app users, not for internal developers accessing AWS resources.
upvoted 1 times
...
EllenLiu
4 months ago
Selected Answer: C
AWS Cognito is designed for authentication and access control for web or mobile app users, not for internal developers accessing AWS resources.
upvoted 1 times
EllenLiu
4 months ago
Sorry, go with B.
upvoted 1 times
...
...
Cpso
4 months, 4 weeks ago
Selected Answer: B
good practice should B. but map role to Identity center federated to corporate IDP.
upvoted 2 times
...
Bwhizzy
6 months, 2 weeks ago
Selected Answer: B
B is the right answer. IAM Role
upvoted 2 times
...
[Removed]
8 months, 1 week ago
B sounds right
upvoted 3 times
...
aragon_saa
8 months, 2 weeks ago
Selected Answer: B
Answer is B
upvoted 3 times
...
muhammadahmer36
8 months, 2 weeks ago
Create an AWS Cognito user pool. Grant developers access to AWS resources by using the user pool.
upvoted 1 times
mk168898
5 months, 2 weeks ago
cognito for app user auth, qns asking for access to AWS resource. your answer is wrong
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago