
AWSCertified Solutions Architect - Associate
Domain 1Objective 3
Task 1.3: Determine Appropriate Data Security Controls SAA-C03 Practice Questions (Page 3)
Part of the Design Secure Architectures domain, which makes up ~18% of our current practice bank. AWS does not publish an official question count, but from its 130-minute exam (~50–85 total, ~9–15 in this domain), expect 3–5 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)
25questions here
5free pages
11concepts
Questions 11–15
- 11
A company stores sensitive data in an Amazon S3 bucket. The security team wants to deny access to this bucket for all IAM principals except those explicitly allowed by a specific IAM policy. Which type of policy should be used to achieve this?
Select an answer first - 12
A company wants to allow a specific IAM user to manage a customer-managed key in AWS KMS. Which type of policy should be used to grant this permission?
Select an answer first - 13
A company has a web application that uses an Application Load Balancer (ALB) and an Amazon RDS database. The security team requires that all data be encrypted in transit and at rest. The ALB uses an ACM certificate for HTTPS. The RDS database is encrypted with a KMS key. What additional configuration is needed to ensure data is encrypted in transit between the ALB and the RDS database?
Select an answer first - 14
A company needs to automatically move objects from Amazon S3 Standard to S3 Glacier Instant Retrieval after 90 days and then delete them after 7 years. Which AWS feature should be used to implement this?
Select an answer first - 15
A company uses AWS Certificate Manager (ACM) to manage TLS certificates for its Application Load Balancer. What is the default behavior for certificate renewal in ACM?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by AWS. “SAA-C03” is a trademark of its owner, used for identification only.