SAA-C03 exam dumps

SAA-C03 practice question 25 of 553

AWS Certified Solutions Architect - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

SAA-C03 Question 25

Select 2

A company is setting up an AWS environment for their new application and is focused on implementing security best practices. They want to ensure that their IAM users and roles adhere to the principle of least privilege. Which of the following actions align with this principle? (Select TWO.)

  1. A

    Grant permissions to users based on their specific job responsibilities.

  2. B

    Assign the AdministratorAccess policy to all IAM users to ensure they can perform any required task.

  3. C

    Regularly review and remove unused IAM roles and permissions.

  4. D

    Use inline policies instead of managed policies for all users to simplify permission management.

  5. E

    Allow users to self-assign additional permissions when needed.

Show answer and explanation

Correct answers: A, C

Explanation

The principle of least privilege requires granting only the permissions necessary for users to perform their tasks and regularly reviewing permissions to remove unnecessary access. This reduces the risk of unauthorized or accidental misuse of resources. Granting excessive permissions, allowing users to self-assign permissions, or mismanaging policies can lead to security vulnerabilities.

  • A. Correct.

    This aligns with the principle of least privilege because it ensures that users only have the permissions needed to perform their specific tasks, minimizing unnecessary access.

  • B. Incorrect.

    This violates the principle of least privilege by granting excessive permissions to all users, which increases the risk of accidental or malicious misuse.

  • C. Correct.

    Regularly reviewing and removing unused roles and permissions ensures that access is not unnecessarily granted, aligning with the principle of least privilege.

  • D. Incorrect.

    Using inline policies for all users does not necessarily simplify permission management and is not directly related to the principle of least privilege.

  • E. Incorrect.

    Allowing users to self-assign permissions violates the principle of least privilege as it can lead to granting excessive or inappropriate permissions.

Timed practice exam

Take a SAA-C03 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam