Pair your devices with a code and playback position follows you: pause on this device, hit resume on the other. Position is saved to the site every minute and on pause.
Open this panel on your other device and enter the same code.
20 questions, four options each, one correct answer, no partial credit. Answers and explanations below.
⚠️ These are exam-styled questions written from the SAA-C03 task statements and AWS documentation. They are not the AWS Official Practice Question Set and are not calibrated against real exam items. A good score here means you understand Domain 1 — not that you'll score 720.
1. An IAM role in account A has no identity-based policy attached. A bucket in account A has a
bucket policy that allows s3:GetObject to that role's ARN. What happens when the role calls
GetObject?
2. A CI job assumes deploy-role, and from that session assumes prod-role with
--duration-seconds 28800. Both roles have a 12-hour maximum session duration. What happens?
3. An SCP attached to an OU denies s3:DeleteBucket. An engineer working in the organization's
management account deletes a bucket. Why did it succeed?
s3:DeleteBucket cannot be denied by an SCP4. Which combination produces an intersection of permissions?
5. An administrator attaches a root-level SCP containing only a Deny for s3:*, and while doing
so detaches FullAWSAccess from the root. What is the resulting state of the member accounts?
6. A requirement says a specific abusive source IP address must be blocked from reaching an application's subnet. Which control?
7. A network ACL has an inbound rule allowing TCP 443 from 0.0.0.0/0. Clients complete the TCP
handshake but receive no response. What is the most likely cause?
8. On-premises servers must access Amazon S3 privately over AWS Direct Connect, without traversing the internet. What do you create?
9. A team creates an S3 gateway endpoint to keep bucket traffic off the internet. An auditor asks whether users can still copy data to buckets in third-party accounts. What is the answer for the default configuration?
10. An application sits behind a Network Load Balancer and must be protected against SQL injection. What is the correct change?
11. You must deploy a new WAF rule against production traffic with no risk of blocking legitimate users while you validate it. Which rule action?
12. Which statement about AWS Shield Standard is correct?
13. A mobile app must upload objects directly to Amazon S3 under a per-user prefix, using the signed-in user's identity. Which Cognito component is required?
14. You need to share an encrypted EBS snapshot with a different AWS account. The volume is
currently encrypted with the aws/ebs AWS managed key. What must change?
kms:Decrypt on the AWS managed key15. An administrator with kms:* in their IAM policy receives AccessDeniedException when
calling kms:Encrypt on a key in their own account. What is the most likely cause?
16. Which KMS key type can only be rotated manually (by creating a new key)?
AWS_KMS origin17. A backup taken in 2024 has leaked. The KMS key that protected it has since been rotated twice with automatic rotation. What is the security impact of those rotations on the leaked backup?
18. An organization changes a bucket's default encryption from SSE-S3 to SSE-KMS. The bucket holds 40 million existing objects. What is the state of those objects, and what is the documented remedy?
19. A records-retention requirement states that records must be undeletable for seven years by any user, including the account root user. Which configuration meets it?
s3:DeleteObject to all principals20. A bucket policy denies all S3 actions to all principals. An S3 Lifecycle rule on the same bucket has an expiration action set to 30 days. What happens to objects older than 30 days?
1 — B. "The resulting permissions are the union of the permissions of the two types. If an action is allowed by an identity-based policy, a resource-based policy, or both, then AWS allows the action." A is wrong because a resource policy granting access to a same-account principal needs no identity policy: "When a resource-based policy grants access to a principal in the same account, no additional identity-based policy is required." C inverts the truth — resource policies work in both cases, but cross-account additionally requires the caller's identity policy. D confuses the union rule with session duration.
2 — D. "if you assume a role using role chaining and provide a DurationSeconds parameter value greater than one hour, the operation fails." Note the word fails — it does not silently truncate, which rules out C. The 12-hour role setting is irrelevant once chaining, which rules out A and B.
3 — B. "SCPs don't affect users or roles in the management account. They affect only the member accounts in your organization." A is wrong in an important way: SCPs do restrict a member account's root user — it's the management account that's exempt, not root users generally. C is false and D invents a propagation excuse.
4 — B. "When AWS evaluates the identity-based policies and permissions boundary for a user, the resulting permissions are the intersection of the two categories." A is the one union in the set. C and D aren't separate policy types — multiple identity policies and multiple statements simply aggregate as grants.
5 — C. Allow requires an explicit Allow at every level: "there must be an explicit Allow
statement at every level from the root through each OU in the direct path to the account." With
FullAWSAccess gone and only a Deny at the root, AWS's own scenario says "all member accounts get no
service access." B misapplies the "SCPs don't grant" rule — true, but SCPs still act as a ceiling
that must allow.
6 — B. "You can specify allow rules, but not deny rules" for security groups, which eliminates A and C. Blocking a source requires a deny rule, and only a network ACL has them. D is the wrong layer entirely.
7 — C. NACLs are stateless: "Return traffic … Must be explicitly allowed." A handshake completing means inbound worked; the response being lost points at the missing outbound rule. B would have blocked the inbound too. D would have prevented the handshake.
8 — B. A gateway endpoint works through the VPC route table, so it serves traffic originating in that VPC — an on-premises network can't use it. An interface endpoint presents a private IP on an ENI that on-premises networks reach over Direct Connect. C and D are internet paths, which the requirement excludes.
9 — C. "The default VPC endpoint policy allows all actions by all principals on all resources over the VPC endpoint." The endpoint changed the path, not the permissions. A and D invent restrictions the endpoint does not impose; B describes what you'd have to write yourself.
10 — C. WAF's supported resources are CloudFront, API Gateway REST API, ALB, AppSync, Cognito user pool, App Runner, Bedrock AgentCore Gateway, Verified Access and Amplify — NLB is not on the list, so A and B are impossible. D is the wrong control: Shield handles DDoS, not SQL injection, and Shield Standard isn't something you enable.
11 — B. "You can use the Count action to track your web traffic without modifying how you handle it … This lets you confirm your new configuration settings before you switch your rules to allow or block matching requests." A blocks real users while you find out. C and D change the user experience rather than observing it.
12 — C. "AWS Shield Standard is automatically included at no extra cost beyond what you already pay for AWS WAF and your other AWS services." D describes Shield Advanced, which lists "dedicated support from the Shield Response Team (SRT)" among its features.
13 — B. Only an identity pool issues AWS credentials: "An identity pool issues AWS credentials for your app to serve resources to users." A user pool returns JWTs, which an S3 API call cannot use directly. D is the classic high-overhead anti-pattern.
14 — B. "You cannot share resources encrypted under an AWS managed key with other accounts." And C is impossible in practice because you cannot change an AWS managed key's policy — "you cannot change any properties of AWS managed keys, rotate them, change their key policies." D is unrelated.
15 — B. "Unless the key policy explicitly allows it, you cannot use IAM policies to allow access to a KMS key. Without permission from the key policy, IAM policies that allow permissions have no effect." A and C are possible in principle but B is the specific documented trap. D is false — grants are one of three mechanisms, not the only one.
16 — C. Manual rotation is required for "Asymmetric KMS keys, HMAC KMS keys, and KMS keys in custom key stores." A supports automatic and on-demand; B supports on-demand; D is rotated automatically by AWS every ~365 days and you cannot change that.
17 — C. "Key rotation has no effect on the data that the KMS key protects. It does not rotate the data keys that the KMS key generated or re-encrypt any data protected by the KMS key. Key rotation will not mitigate the effect of a compromised data key." B is also wrong because KMS retains all key material and "automatically chooses the correct key material" on decrypt.
18 — B. "When you change the default encryption configuration of your bucket to SSE-KMS, the encryption type of the existing Amazon S3 objects in the bucket is not changed", and the documented remedy is S3 Batch Operations: "You can use the Copy objects action to copy existing objects, which writes them back to the same bucket as SSE-KMS encrypted objects." C confuses lifecycle transitions (storage class) with encryption; D confuses Bucket Keys (a cost optimisation) with re-encryption.
19 — C. Compliance mode is the only option where "a protected object version can't be overwritten
or deleted by any user, including the root user in your AWS account", and Object Lock "works only in
buckets that have S3 Versioning enabled." B leaves a bypass path for holders of
s3:BypassGovernanceRetention. A is the trap question 20 is about. D doesn't provide a retention
guarantee.
20 — B. "You can't use a bucket policy to prevent deletions or transitions by an S3 Lifecycle rule. For example, even if your bucket policy denies all actions for all principals, your S3 Lifecycle configuration still functions as normal." A applies the explicit-deny rule to something that isn't a principal making a request. C invents a lifecycle service role. D is false — the configuration saves and runs.
| Score | Read this as |
|---|---|
| 18–20 | Domain 1 is solid. Move to Domain 2 and come back to this quiz a week before the exam. |
| 14–17 | Good. Re-read the lessons behind every miss — the explanations name them. |
| 10–13 | You know the services but not the mechanics. Re-do lessons 1 and 5, then the lab. |
| < 10 | Work through the module in order. Don't take another quiz until you've done Part 5 of the lab. |
Common miss patterns, and what they mean: