Skip to content
BytePatterns

SAP-C02 · Domain 1: Design Solutions for Organizational Complexity · 26% of the exam

Task 1.2: Prescribe security controls.

Security across an organization: cross-account roles, IAM Identity Center with an outside identity provider, encryption keys and certificates shared between accounts, and one place where security findings and audit trails from every account arrive.

Study it

  • Cross-account access, IAM Identity Center with an external identity provider, and ABAC

    Partly covered by: Shared Responsibility & IAM

  • Keys and certificates across accounts: KMS key policies, multi-Region keys, Private CA

    Partly covered by: KMS, Envelope Encryption & Private CA

  • Central security findings and audit: organization trails, Security Hub CSPM, GuardDuty and Detective

    Lesson coming

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 1

A company manages its workforce in an external identity provider that supports SAML 2.0 and SCIM. Employees need access to 200 accounts in AWS Organizations. When HR adds a user to a group or removes a user, the change must reach AWS without manual work, and access must be granted by group and account. The company does not want IAM users. Which solution has the LEAST operational overhead?

  1. ACreate a SAML identity provider and federated IAM roles in each of the 200 accounts, and map the identity provider's groups to the roles
  2. BConnect the identity provider to AWS Directory Service AD Connector and grant access to the directory groups with IAM policies in each account
  3. CUse the external provider as the IAM Identity Center identity source with SCIM provisioning, and assign permission sets to groups per account
  4. DCreate an Amazon Cognito identity pool federated with the provider and give employees temporary credentials for each account through it
Show the answer and why
  • ACreate a SAML identity provider and federated IAM roles in each of the 200 accounts, and map the identity provider's groups to the roles

    Incorrect

    IAM SAML federation works, but the provider and roles must be created and kept current in every account, which is far more work than one central configuration.

  • BConnect the identity provider to AWS Directory Service AD Connector and grant access to the directory groups with IAM policies in each account

    Incorrect

    AD Connector is a directory gateway that redirects requests to an on-premises Microsoft Active Directory. It does not connect a SAML and SCIM identity provider, and per-account IAM policies would still need to be maintained.

  • CUse the external provider as the IAM Identity Center identity source with SCIM provisioning, and assign permission sets to groups per account

    Correct

    IAM Identity Center can use an external identity provider as its identity source and synchronize users and groups automatically over SCIM. Permission sets assigned to groups give access to many accounts from one place.

  • DCreate an Amazon Cognito identity pool federated with the provider and give employees temporary credentials for each account through it

    Incorrect

    Cognito identity pools give the users of your own applications temporary credentials. Workforce access to AWS accounts is what IAM Identity Center is for.

"Changes flow in automatically" points to SCIM provisioning, and "many accounts by group" points to IAM Identity Center permission sets.

Question 2 · choose 1

A company has 150 accounts in AWS Organizations and runs workloads in four Regions. The security team wants Amazon GuardDuty and AWS Security Hub CSPM turned on in every current and future member account, findings from every account and Region visible in one security tooling account, and high-severity findings sent to the on-call paging system through a single integration. What should a solutions architect do?

  1. ACreate an organization trail in AWS CloudTrail and an Amazon EventBridge rule in the logging account that matches GuardDuty and Security Hub CSPM findings recorded in the trail
  2. BMake the security account delegated administrator for both services with auto-enable, aggregate findings in one home Region, and add one EventBridge rule there
  3. CDeploy a CloudFormation StackSet that turns on both services in every account and creates an EventBridge rule and SNS topic in each account and Region for the pager
  4. DCreate an AWS Config aggregator in the security account for all accounts and Regions, and send its compliance change notifications for GuardDuty findings to the pager
Show the answer and why
  • ACreate an organization trail in AWS CloudTrail and an Amazon EventBridge rule in the logging account that matches GuardDuty and Security Hub CSPM findings recorded in the trail

    Incorrect

    CloudTrail records API activity in the accounts. Findings are produced by GuardDuty and Security Hub CSPM and are delivered as events, not collected through a trail.

  • BMake the security account delegated administrator for both services with auto-enable, aggregate findings in one home Region, and add one EventBridge rule there

    Correct

    A delegated administrator can manage GuardDuty and Security Hub CSPM for the organization's members. Cross-Region aggregation brings findings to the home Region, and Security Hub CSPM sends findings to EventBridge, where one rule can route them.

  • CDeploy a CloudFormation StackSet that turns on both services in every account and creates an EventBridge rule and SNS topic in each account and Region for the pager

    Incorrect

    This enables the services, but findings stay in each account and Region and the pager needs hundreds of separate subscriptions instead of one central integration.

  • DCreate an AWS Config aggregator in the security account for all accounts and Regions, and send its compliance change notifications for GuardDuty findings to the pager

    Incorrect

    A Config aggregator collects configuration and compliance data from AWS Config. It does not collect GuardDuty threat findings.

Central security operations combine three features: a delegated administrator per service with auto-enable for members, cross-Region aggregation to one home Region, and EventBridge rules on the aggregated findings.

Question 3 · choose 2

An IAM role in an analytics account must read objects from an S3 bucket in a data account. The bucket uses SSE-KMS with a customer managed key in the data account, and the data must stay encrypted with that key. The bucket policy already allows the role s3:GetObject, but every read fails with an access denied error from AWS KMS. Which changes are required? (Choose TWO.)

  1. ATurn on S3 Bucket Keys for the bucket so that reads use a bucket-level key instead of calling AWS KMS
  2. BAdd a statement to the key policy in the data account that allows the analytics account role to call kms:Decrypt
  3. CAdd kms:Decrypt for the analytics role to the bucket policy so that S3 passes the permission on to AWS KMS
  4. DRe-encrypt the objects with the AWS managed key for Amazon S3 and share that key with the analytics account
  5. EAdd an IAM policy to the role in the analytics account that allows kms:Decrypt on the key's ARN
Show the answer and why
  • ATurn on S3 Bucket Keys for the bucket so that reads use a bucket-level key instead of calling AWS KMS

    Incorrect

    S3 Bucket Keys reduce the number of requests to AWS KMS, but the caller still needs permission to use the KMS key, so the error remains.

  • BAdd a statement to the key policy in the data account that allows the analytics account role to call kms:Decrypt

    Correct

    Cross-account use of a KMS key requires the key policy in the owning account to give the external account or its role permission to use the key.

  • CAdd kms:Decrypt for the analytics role to the bucket policy so that S3 passes the permission on to AWS KMS

    Incorrect

    Permission to use a KMS key comes from the key policy and IAM policies. A bucket policy controls access to the bucket and its objects, not to the KMS key.

  • DRe-encrypt the objects with the AWS managed key for Amazon S3 and share that key with the analytics account

    Incorrect

    The data must stay on the customer managed key. Besides, an AWS managed key can be used only by principals in its own account, its permissions cannot be managed, and resources encrypted under it cannot be shared with other accounts.

  • EAdd an IAM policy to the role in the analytics account that allows kms:Decrypt on the key's ARN

    Correct

    The external account must also delegate the key policy permission to its role with an IAM policy. Neither the key policy nor the IAM policy alone is enough.

Cross-account KMS needs both halves: the key policy says who can use the key, and the IAM policy in the other account says who does. The bucket policy only covers S3.

Question 4 · choose 1

A company with 80 accounts in AWS Organizations must find every S3 bucket, IAM role, KMS key and Lambda function whose resource-based policy grants access to principals outside the organization. New policies that do so must be reported continuously to a security account. Which solution meets these requirements with the LEAST effort?

  1. ADeploy the AWS Config managed rule that checks for public read access on S3 buckets to every account with a conformance pack
  2. BRun Amazon Macie in every account and review its bucket inventory for buckets shared with other accounts
  3. CUse the AWS Trusted Advisor security checks from the management account to list resources shared outside the organization
  4. DCreate an organization-wide IAM Access Analyzer external access analyzer in a delegated administrator account
Show the answer and why
  • ADeploy the AWS Config managed rule that checks for public read access on S3 buckets to every account with a conformance pack

    Incorrect

    That rule looks only at public read access on S3 buckets. It does not evaluate IAM role trust policies, key policies or Lambda function policies, or access granted to specific external accounts.

  • BRun Amazon Macie in every account and review its bucket inventory for buckets shared with other accounts

    Incorrect

    Macie discovers sensitive data in S3. It does not analyze IAM roles, KMS keys or Lambda functions for external access.

  • CUse the AWS Trusted Advisor security checks from the management account to list resources shared outside the organization

    Incorrect

    Trusted Advisor runs a fixed set of best-practice checks. It does not analyze the resource policies of these resource types against an organization boundary.

  • DCreate an organization-wide IAM Access Analyzer external access analyzer in a delegated administrator account

    Correct

    An external access analyzer with the organization as its zone of trust flags any supported resource that grants access to a principal outside the organization, and it reanalyzes when policies change.

"Shared outside the organization" is the job of an organization-level IAM Access Analyzer: the organization is the zone of trust and anything beyond it becomes a finding.

Question 5 · choose 1

A consumer mobile app signs customers in with the company's own OpenID Connect (OIDC) provider. A new feature must let the app upload videos straight to an S3 bucket and write a metadata item for each video to an existing DynamoDB table whose partition key is the customer's Amazon Cognito identity ID, with no traffic passing through company servers. Each customer may touch only their own S3 prefix and their own items, the app must not contain long-term access keys, and the team does not want to build or run a service that hands out access. Which solution meets these requirements?

  1. ASend the OIDC token to AWS STS AssumeRoleWithWebIdentity for a role whose policy scopes access with the provider's subject claim
  2. BAdd the OIDC provider to a Cognito identity pool whose role scopes S3 and DynamoDB access with the caller's identity ID
  3. CAdd an API Gateway and Lambda endpoint that checks the customer and returns a presigned URL for each upload and writes the metadata item
  4. DHave the app call S3 and DynamoDB directly with the ID token that the OIDC provider issues at sign-in
Show the answer and why
  • ASend the OIDC token to AWS STS AssumeRoleWithWebIdentity for a role whose policy scopes access with the provider's subject claim

    Incorrect

    OIDC federation does exchange the token for temporary credentials, but the policy variables would carry the provider's own user ID. The Cognito identity ID in the table's partition key is not that value, so the dynamodb:LeadingKeys condition could never match a customer's items.

  • BAdd the OIDC provider to a Cognito identity pool whose role scopes S3 and DynamoDB access with the caller's identity ID

    Correct

    The identity pool exchanges the provider's ID token for temporary AWS credentials. Its role policy can use the cognito-identity.amazonaws.com:sub variable, which holds the identity ID, in S3 resource paths and in the dynamodb:LeadingKeys condition, so each customer reaches only their own prefix and partition, with no server in the path.

  • CAdd an API Gateway and Lambda endpoint that checks the customer and returns a presigned URL for each upload and writes the metadata item

    Incorrect

    Presigned URLs give time-limited access to S3 objects without putting keys in the app, but they cover only S3. The metadata writes would pass through company code, and the team would build and run the service that hands out access.

  • DHave the app call S3 and DynamoDB directly with the ID token that the OIDC provider issues at sign-in

    Incorrect

    Requests to AWS services must be signed with AWS credentials. A provider's token is not one; it has to be exchanged for temporary AWS security credentials first.

The decisive constraints are direct access to two AWS services, per-customer isolation keyed on the Cognito identity ID, and no access-issuing service to run. Presigned URLs solve the S3 half but need a backend and do not cover DynamoDB, and a provider token alone is not an AWS credential. Direct OIDC federation yields credentials, but its policy variables identify the user by the provider's ID, not by the identity ID that partitions the table. A Cognito identity pool turns the OIDC token into temporary credentials, and policy variables on the identity ID confine each customer to their own prefix and items.

Question 6 · choose 1

A billing portal signs customers in with its own session system and keeps PDF invoices in a private S3 bucket that has S3 Block Public Access turned on. Customers download about 2,000 invoices a month. Each download link must open only the one invoice it was made for and must stop working after 5 minutes. Compliance forbids storing or caching invoice files anywhere outside the bucket, and the team wants to add as little new infrastructure as possible. Which solution meets these requirements?

  1. AHave the portal's backend role create an S3 presigned GET URL for the requested invoice that expires after 5 minutes
  2. BPut a CloudFront distribution with origin access control in front of the bucket and issue CloudFront signed URLs valid for 5 minutes
  3. CAllow s3:GetObject in the bucket policy only for requests whose aws:Referer header is the portal's domain
  4. DCall GetFederationToken with a session policy for the one invoice and return the temporary credentials to the customer's browser
Show the answer and why
  • AHave the portal's backend role create an S3 presigned GET URL for the requested invoice that expires after 5 minutes

    Correct

    A presigned URL grants time-limited access to one object without changing the bucket policy, and it uses the credentials of the principal that created it. The browser fetches the file straight from the bucket, so no new service and no copy outside S3 is involved.

  • BPut a CloudFront distribution with origin access control in front of the bucket and issue CloudFront signed URLs valid for 5 minutes

    Incorrect

    Signed URLs with an expiration time are the CloudFront way to serve private content, but they need a distribution and trusted key groups, and CloudFront adds objects to its edge caches when they are requested, which the compliance rule forbids.

  • CAllow s3:GetObject in the bucket policy only for requests whose aws:Referer header is the portal's domain

    Incorrect

    AWS warns that a referer header can be forged, and aws:Referer is not one of the condition keys that make a policy non-public, so Block Public Access rejects the policy. The access would not expire either.

  • DCall GetFederationToken with a session policy for the one invoice and return the temporary credentials to the customer's browser

    Incorrect

    GetFederationToken suits a proxy application that hands out scoped temporary credentials, but its sessions last at least 900 seconds (15 minutes), and it must be called with an IAM user's long-term credentials rather than the portal's role.

Expiring, per-object links to private S3 data can come from S3 presigned URLs or from CloudFront signed URLs. Here two more constraints decide it: nothing may be cached outside the bucket, and the team wants no new infrastructure, which rules out a CloudFront distribution and its edge caches. A Referer condition is neither secure nor allowed under Block Public Access, and federation tokens cannot be shorter than 15 minutes. A 5-minute presigned URL created by the portal's backend meets every constraint.

Question 7 · choose 1

A security team wants one data lake in its own account with security logs from AWS services across the organization plus logs from on-premises and SaaS tools, all normalized to one open schema so its analytics tools can query them together. Which service fits?

  1. AAmazon Security Lake
  2. BAWS Config aggregator in the security account
  3. CAmazon Inspector with a delegated administrator
  4. DCloudWatch Logs subscriptions in each account
Show the answer and why
  • AAmazon Security Lake

    Correct

    Security Lake centralizes security data from AWS, on-premises and SaaS sources into a data lake and converts it to the Open Cybersecurity Schema Framework.

  • BAWS Config aggregator in the security account

    Incorrect

    An aggregator collects configuration and compliance data, not security logs from many sources.

  • CAmazon Inspector with a delegated administrator

    Incorrect

    Inspector scans for vulnerabilities; it is not a log data lake.

  • DCloudWatch Logs subscriptions in each account

    Incorrect

    Subscriptions stream logs but do not normalize sources into one open schema in a data lake.

A normalized, central security data lake is Amazon Security Lake.

Question 8 · choose 1

A document-sharing application needs fine-grained authorization: which of its users can view, edit or share which documents. Rules change often, and the team wants them managed as policies outside the application code. Which service fits?

  1. AAWS WAF rules on the load balancer in front of the application
  2. BAmazon Verified Permissions policies for the application's resources
  3. CIAM policies with one IAM role per application user that the app assumes
  4. DAmazon Cognito user pool groups only
Show the answer and why
  • AAWS WAF rules on the load balancer in front of the application

    Incorrect

    WAF filters web requests; it does not decide who may edit a document.

  • BAmazon Verified Permissions policies for the application's resources

    Correct

    Verified Permissions is a fine-grained permissions management and authorization service for custom applications.

  • CIAM policies with one IAM role per application user that the app assumes

    Incorrect

    IAM controls access to AWS resources, not permissions inside a custom application for each end user.

  • DAmazon Cognito user pool groups only

    Incorrect

    Groups authenticate and group users but do not express per-document permissions.

Externalized, fine-grained application authorization is Amazon Verified Permissions.

Question 9 · choose 1

Developers change IAM policies in CloudFormation templates through a pipeline. The security team wants the pipeline to fail automatically when a change would grant new access compared with the approved version of a policy. Which approach fits?

  1. ARun IAM Access Analyzer policy validation in CI and fail on its findings
  2. BRun IAM Access Analyzer unused access analysis once a month in each account
  3. CTurn on CloudTrail data events for IAM
  4. DRun IAM Access Analyzer custom policy checks for new access in CI
Show the answer and why
  • ARun IAM Access Analyzer policy validation in CI and fail on its findings

    Incorrect

    Policy validation checks a policy against IAM policy grammar and AWS best practices and reports errors and warnings. It does not compare the change with the approved version to find new access.

  • BRun IAM Access Analyzer unused access analysis once a month in each account

    Incorrect

    Unused access findings look at granted access after deployment, not at a policy change in the pipeline.

  • CTurn on CloudTrail data events for IAM

    Incorrect

    CloudTrail records API activity after the fact; it does not block a deployment.

  • DRun IAM Access Analyzer custom policy checks for new access in CI

    Correct

    Custom policy checks can check a policy for new access against your security standards.

Catching new access in a pipeline is done with Access Analyzer custom policy checks.

Practise domain 1 →Practise all domains →