Prepstellar

SAA-C03 · Practice set 6 of 9

Multi-Account Access and Governance: 10 practice questions

10 questions · Untimed · Free

10 free SAA-C03 practice questions on Multi-Account Access and Governance, with an explanation for every answer. Untimed. The full mock exam and the timed version are in the app.

Set 6 · Multi-Account Access and Governance · 10 questions Read the lesson
  1. Question 1 of 10

    What does an AWS Organizations service control policy define?

    1. AThe account templates used to provision resources through Account Factory
    2. BThe maximum available permissions for IAM users and roles in member accounts
    3. CThe user and group assignments created in the IAM Identity Center directory
    4. DThe permissions granted directly to users and roles in the management account
    Show the answer

    An SCP is a ceiling for member-account identities; actual access still comes from IAM or resource policies.

    Next → 1 / 10
  2. Question 2 of 10

    Which AWS Control Tower feature standardizes new-account provisioning?

    1. AAccount Factory with configurable account templates
    2. BThe dashboard with organization-wide views of accounts and noncompliant resources
    3. CAn SCP attached directly to the management account
    4. DAn IAM Identity Center account instance for isolated applications
    Show the answer

    Account Factory is the Control Tower component that automates account creation from pre-approved configurations.

    Next → 2 / 10
  3. Question 3 of 10

    Which service can centrally manage workforce access to multiple AWS accounts?

    1. AAWS Organizations service control policies
    2. BAWS IAM Identity Center
    3. CAWS Control Tower Account Factory
    4. DAWS Control Tower dashboard
    Show the answer

    IAM Identity Center centralizes workforce account access, while the neighboring governance features provision, constrain, or monitor accounts.

    Next → 3 / 10
  4. Question 4 of 10

    An administrator attaches AdministratorAccess in a member account, but an inherited SCP denies the required action. What is the result?

    1. AThe action succeeds after the SCP grants the missing permission directly.
    2. BThe action remains unavailable because the SCP limits maximum permissions.
    3. CThe action moves automatically to the management account where the SCP is ignored.
    4. DThe action succeeds because AdministratorAccess overrides organization policies.
    Show the answer

    Effective access needs both a grant from the account and room under every applicable organization guardrail.

    Next → 4 / 10
  5. Question 5 of 10

    What is the role of the AWS Control Tower dashboard?

    1. ADefinition of the maximum permissions available in each member account
    2. BCentral oversight of accounts, enabled controls, and noncompliant resources
    3. CDirect issuance of temporary credentials to every workforce user
    4. DCreation of a destination-account trust policy for cross-account access
    Show the answer

    The dashboard is the visibility surface; Account Factory provisions accounts and controls enforce or assess governance rules.

    Next → 5 / 10
  6. Keep the ones you got wrong

    In the app, every question you miss comes back exactly when you’re about to forget it.

  7. Question 6 of 10

    Which statement describes a Control Tower landing zone?

    1. AA governed multi-account environment based on security and compliance practices
    2. BA directory instance limited to isolated applications in one AWS account
    3. CA single identity policy that grants every administrator access to all organization accounts
    4. DA temporary role session used to access one destination account
    Show the answer

    The landing zone is Control Tower's multi-account foundation and contains the accounts and organizational structure subject to governance.

    Next → 6 / 10
  8. Question 7 of 10

    A security architect needs a policy ceiling for identities in selected organizational units, without adding an account-provisioning workflow. What should be used?

    1. AService control policies attached at the appropriate organization levels
    2. BIAM Identity Center account instances enabled in every member account
    3. CAWS Control Tower Account Factory templates for the selected units
    4. DThe Control Tower dashboard with a filter for the selected units
    Show the answer

    The requirement is a narrow permissions guardrail, so SCPs fit without introducing the broader Control Tower operating layer.

    Next → 7 / 10
  9. Question 8 of 10

    A new organization needs standardized account creation, continuous visibility, and company-wide governance controls. Administrators also want the AWS services underneath to remain available for extension. Which choice best fits?

    1. AAdopt AWS Control Tower and use its landing zone, Account Factory, dashboard, and controls.
    2. BUse SCPs alone and treat them as the account factory and monitoring dashboard.
    3. CUse IAM Identity Center alone to provision accounts and detect policy non-conformance.
    4. DCreate one cross-account IAM role and use its trust policy directly as the organization governance framework.
    Show the answer

    The combination of provisioning, oversight, controls, and extensibility identifies Control Tower rather than one underlying permission or identity feature.

    Next → 8 / 10
  10. Question 9 of 10

    A member account needs an action, an IAM policy grants it, and an OU-level SCP allows it. The organization requires all three facts to be honored without letting the SCP create access. What follows?

    1. AThe action is evaluated only by the SCP, so the IAM policy is ignored.
    2. BThe action succeeds solely because the SCP itself grants the permission.
    3. CThe action can succeed because the IAM grant is within the SCP ceiling.
    4. DThe action fails because an SCP can never participate in an allowed request.
    Show the answer

    A valid member-account request needs a positive IAM or resource-policy grant and no blocking organization-policy limit.

    Next → 9 / 10
  11. Question 10 of 10

    A company wants an SCP to constrain a delegated administrator member account but leave management-account identities unaffected. The policy must act only as a ceiling. Is that design valid?

    1. AYes; SCPs affect delegated administrator member accounts but not management-account identities.
    2. BNo; an SCP must grant permissions before it can constrain the delegated account.
    3. CNo; delegated administrator member accounts are automatically exempt from every SCP attached anywhere in the organization.
    4. DYes; the SCP grants the delegated account access and denies the management account.
    Show the answer

    The scope and mechanism both align: delegated administrators remain member accounts, while management-account users and roles are outside SCP effect.

    Next → 10 / 10
  12. You’ve finished this set

    That’s 10 questions on Multi-Account Access and Governance. In the app the ones you miss come back exactly when you’re about to forget them.

The whole course, on your phone

Lessons you can read, audio you can listen to on the way to work, and practice that remembers what you got wrong.