Design secure access to AWS resources.
6 practice questions under this official exam objective (SAA-C03) — each with the community-verified answer, a full option-by-option explanation and instant feedback.
API Gateway Resource Policy for IP Restriction
This page explains how to restrict access to an Amazon API Gateway HTTP API using a resource policy based on the client's source IP address, ensuring
EKS IRSA Pod Access Control with IAM Roles
This question tests the implementation of fine-grained access control for Amazon EKS pods using IAM Roles for Service Accounts (IRSA). It establishes
S3 Multi-Region Access Points for Low-Latency Global Storage
This question evaluates the use of Amazon S3 Multi-Region Access Points (MRAP) to provide a single global endpoint that routes traffic to the nearest
Least Overhead Identity Integration with On-Prem AD
This question evaluates the optimal method for integrating on-premises Active Directory with AWS Organizations to provide centralized identity managem
Amazon Security Lake for Centralized Security Data
Amazon Security Lake is the AWS service designed to automatically centralize security data from multiple sources into a purpose-built data lake in Ama
AWS SMB Storage Solution Least Overhead
This question identifies Amazon FSx for Windows File Server as the optimal solution for SMB-based shared storage on AWS, minimizing administrative ove