SAA-C03 exam dumps

SAA-C03 practice question 14 of 553

AWS Certified Solutions Architect - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

SAA-C03 Question 14

Single answer

Your organization uses AWS Organizations to manage multiple AWS accounts. You need to ensure that IAM users and roles within a member account can access certain resources in another member account securely and with minimal administrative overhead. Which solution satisfies this requirement?

  1. A

    Create cross-account IAM roles in the target account and grant permission to the source account.

  2. B

    Manually create identical IAM users and policies in both accounts.

  3. C

    Use Service Control Policies (SCPs) to grant access to the required resources across accounts.

  4. D

    Enable resource sharing through AWS Resource Access Manager (RAM) for the required resources.

Show answer and explanation

Correct answer: A

Explanation

The best way to manage access controls across multiple AWS accounts is to use cross-account IAM roles. These roles allow you to securely grant permissions to IAM users or roles in one account to access resources in another account. This approach is scalable, secure, and adheres to AWS best practices. Other options like SCPs, RAM, or duplicating IAM users are either incorrect or unsuitable for this specific scenario.

  • A. Correct.

    Correct. Cross-account IAM roles are the recommended way to allow secure access to resources across AWS accounts. You can create a role in the target account, define a trust relationship with the source account, and grant necessary permissions to the role.

  • B. Incorrect.

    Incorrect. Manually creating identical IAM users and policies in multiple accounts is error-prone, hard to manage, and violates best practices for managing access across accounts.

  • C. Incorrect.

    Incorrect. Service Control Policies (SCPs) control permissions at the organization or account level but cannot directly grant access to resources across accounts. They act as permission boundaries, not access grants.

  • D. Incorrect.

    Incorrect. AWS Resource Access Manager (RAM) is used to share specific resource types across accounts, but it does not provide general access control for IAM users or roles across accounts.

Timed practice exam

Take a SAA-C03 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam