SAA-C03 · Secure Access to AWS Resources
23 cards
Multi-Account Access and Governance
-
Quick check
A company needs its workforce to reach several AWS accounts through one central place. Which service does that?
AThe Control Tower dashboard, which reports on accounts and controls
The dashboard is an oversight surface; it reports on accounts rather than granting people access to them.
BAccount Factory, which provisions accounts
Account Factory creates accounts from templates; it does not manage who signs in to them.
CIAM Identity Center, which manages workforce access
Right. IAM Identity Center centrally manages workforce access to multiple AWS accounts.
3 / 23
-
Quick check
Which statement describes a Control Tower landing zone?
AA governed multi-account environment based on security and compliance practices
Right. The landing zone is the multi-account environment Control Tower sets up and governs.
BA temporary role session used to reach one destination account
A role session is short-lived access to a single account, not a governed multi-account environment.
CA directory instance limited to isolated applications
A directory instance scoped to isolated applications serves one account's applications; it is not the environment itself.
6 / 23
-
Quick check
A team wants new accounts created consistently from pre-approved configurations. Which Control Tower feature does that?
AThe dashboard, which shows provisioned accounts and noncompliant resources
The dashboard gives visibility over accounts that already exist rather than creating them.
BAccount Factory and its configurable templates
Right. Account Factory standardizes and automates the provisioning of new accounts from configurable templates.
CA service control policy attached to the management account
A permissions ceiling limits what identities may do; it does not provision accounts.
9 / 23
-
Keep your progress in the app
That’s 3 of 9 quick checks. In the app they stay answered, and every lesson remembers where you left off.
-
Quick check
An organization needs rules that keep security logs in place and preserve required cross-account access permissions. What provides them?
AAccount Factory templates applied at account creation
A provisioning template shapes a new account once; it does not keep logs and permissions in place afterwards.
BControl Tower controls, which govern accounts on an ongoing basis
Right. Control Tower controls provide ongoing governance and can help create and preserve security logs and required cross-account access permissions.
CThe Control Tower dashboard, by reporting noncompliant resources each day
The dashboard shows what is noncompliant; visibility alone does not create or preserve the logs and permissions.
11 / 23
-
Quick check
An IAM policy in a member account grants an action, and the organizational-unit ceiling allows it as well. What follows?
AThe action fails, because an organization-level limit can never take part in an allowed request
An allowed request is normal: the ceiling participates by not excluding the action, and the identity policy supplies the grant.
BThe action succeeds because the organization-level limit itself supplied the permission
A maximum-permissions policy never grants anything; the permission came from the identity-based policy.
CThe action can succeed: the grant fits inside the ceiling
Right. Effective permissions are the intersection, so a granted action that stays inside the ceiling can proceed.
14 / 23
-
Quick check
A company wants a maximum-permissions policy to constrain a delegated administrator account while leaving management-account identities untouched. Is that design valid?
AYes. A delegated administrator account is still a member account and is affected, while management-account identities are not.
Right. Delegated administrator accounts are member accounts and are reached, while users and roles in the management account are not.
BNo. Delegated administrator accounts are exempt from every such policy.
Delegated administrators are not exempt; being a delegated administrator does not remove the account from member scope.
CNo. The policy must grant the permission before it can limit it.
These policies never grant anything, so granting first is not a precondition for limiting.
16 / 23
-
Quick check
An administrator attaches AdministratorAccess in a member account, but an inherited organization-level policy denies the action. What happens?
AThe action stays unavailable: the ceiling still applies.
Right. Maximum permissions are defined above the account, and no identity policy inside it can exceed them.
BThe action succeeds, because AdministratorAccess overrides organization policy.
A broad identity policy grants generously but still cannot exceed the maximum available permissions.
CThe action moves to the management account, where the ceiling is ignored.
Requests do not relocate; the management-account exception covers identities in that account, not actions attempted in a member account.
18 / 23
-
Quick check
An architect needs a permissions ceiling over selected organizational units and does not want a new account-provisioning workflow. What fits?
AAdopt Control Tower and run its landing zone, Account Factory, and dashboard
Control Tower brings the provisioning and operating layer the requirement explicitly excludes.
BFilter the Control Tower dashboard to those units
Filtering a view changes what is displayed and never limits what an identity may do.
CAttach service control policies at those organizational units
Right. A maximum-permissions guardrail applied at organization, organizational unit, or account level is exactly this mechanism.
21 / 23
-
Quick check
Which pairing of requirement and mechanism is right?
AA ceiling across an organizational unit is set with Account Factory
Account Factory provisions accounts from templates and sets no permission limits.
BA governed landing zone with provisioning and oversight calls for Control Tower, while a maximum-permissions guardrail calls for a service control policy
Right. Those are the two documented selections, and they follow from what each requirement asks for.
CWorkforce access to many accounts is delivered by the Control Tower dashboard
The dashboard reports on accounts, controls, and noncompliant resources; IAM Identity Center is what manages workforce access.
23 / 23
-
9 quick checks · then the test
In the app, finishing the quick checks opens this lesson’s 10-question test, and the ones you miss come back exactly when you’re about to forget them.
The whole course, on your phone
Lessons you can read, audio you can listen to on the way to work, and practice that remembers what you got wrong.