Security is the largest SAA-C03 domain at 30%, roughly one question in three, and it is the one where the "best" answer is least negotiable. Performance and cost questions often have several workable options ranked by degree; security questions have a correct answer and several that leave a hole. This guide covers IAM, encryption, and network security to the depth the exam demands.
For where this sits in the whole exam, see the domains breakdown; for the network-security half, pair it with the VPC guide.
Find out where you stand first
Take the free SAA-C03 sample questions cold (no signup, real exam style), then read on with your gaps in mind. When you are ready for full rehearsal, Preporato's SAA-C03 practice tests include 6 full-length exams (401 questions in total, domain-proportional, every answer explained) for a one-time $19.99 with lifetime access.
IAM: The Core of the Domain
The four identity types. Users (long-lived, a person or app), groups (a bucket of users for shared permissions), roles (temporary credentials assumed by a principal), and policies (JSON documents granting or denying permissions). The exam's strong preference: roles over users with access keys wherever possible, because roles issue short-lived credentials and remove the standing secret that leaks.
Policy evaluation logic, tested directly and often:
- Start from an implicit deny (nothing is allowed by default).
- An explicit Allow in any applicable policy grants access.
- An explicit Deny anywhere overrides any Allow.
So the rule to memorize: explicit deny always wins. A question where a user has an Allow from a group but a Deny from an SCP or a boundary policy resolves to denied. This is the single most-tested IAM mechanic.
Roles for the three big use cases:
- EC2 instance profile: an app on EC2 needs to call S3. Attach a role to the instance, never bake keys into the AMI. The "app needs AWS access without stored credentials" answer is always an instance role.
- Cross-account access: account A assumes a role in account B. The clean way to grant another account (or a vendor) scoped access without sharing credentials.
- Identity federation: corporate users sign in with existing identity (SAML, or web identity via Cognito) and assume a role. The "let 5,000 corporate users use AWS without creating 5,000 IAM users" answer.
Guardrails above IAM. Service Control Policies (SCPs) in AWS Organizations set the maximum permissions an account can have; they do not grant anything, they cap. Permissions boundaries do the same for an individual principal. A scenario about "prevent any user in this account from disabling CloudTrail, even admins" wants an SCP.
Preparing for SAA-C03? Practice with 390+ exam questions
Encryption: At Rest and In Transit
KMS (Key Management Service) is the center of gravity. It manages encryption keys and performs envelope encryption: KMS holds the key that encrypts your data keys, so the small master key stays in KMS while bulk data is encrypted locally with data keys. Know:
- AWS-managed keys vs customer-managed keys (CMK): choose CMK when you need key rotation control, custom key policies, or cross-account key use.
- Encryption at rest is a toggle-plus-key on EBS, S3, RDS, and most storage. Enable it; "data must be encrypted at rest" is a KMS answer.
- Encryption in transit is TLS. "Data must be encrypted in transit" wants HTTPS/TLS, ACM-issued certificates on load balancers.
- CloudHSM is the answer only when the stem demands a dedicated, single-tenant hardware module or specific compliance (FIPS 140-2 Level 3) that managed KMS does not meet.
Secrets belong in Secrets Manager (automatic rotation, the answer when rotation is mentioned) or SSM Parameter Store (cheaper, no built-in rotation), never in code, environment files baked into images, or plaintext user data.
Network and Threat Security
The protective services, and the exact job each does:
Security services by job
| Job | Service |
|---|---|
| Filter malicious L7 web traffic (SQLi, XSS) | AWS WAF |
| Absorb DDoS attacks | AWS Shield (Standard free; Advanced for large-scale) |
| Detect threats from logs and traffic (ML) | Amazon GuardDuty |
| Aggregate security posture and findings | AWS Security Hub |
| Discover and classify sensitive data in S3 | Amazon Macie |
| Record all API calls for audit | AWS CloudTrail |
| Assess resource configuration compliance | AWS Config |
| Automated vulnerability scanning | Amazon Inspector |
The tell-tale keywords: "SQL injection / cross-site scripting" -> WAF; "DDoS" -> Shield; "detect unusual API activity or compromised instances" -> GuardDuty; "find credit-card numbers or PII in a bucket" -> Macie; "who did what, when, for audit" -> CloudTrail.
Master These Concepts with Practice
Our SAA-C03 practice bundle includes:
- 6 full practice exams (390+ questions)
- Detailed explanations for every answer
- Domain-by-domain performance tracking
30-day money-back guarantee
The "Most Secure" Architecture Patterns
Security-domain scenario answers cluster around a few principles the exam rewards every time:
- Least privilege. The correct answer grants the minimum permissions for the task, not
*on a resource. An option with broad admin access is almost always wrong. - Defense in depth. Layer controls: security groups and NACLs, encryption and IAM, private subnets and least-privilege roles.
- No hardcoded credentials. Roles, Secrets Manager, and instance profiles beat any answer that stores a key.
- Private by default. Databases in private subnets, S3 buckets not public, endpoints instead of internet paths.
- Encrypt everywhere it is cheap to. At rest with KMS, in transit with TLS.
Study the domain with weighted depth
Because Security is 30%, it deserves a disproportionate share of study time. The SAA-C03 study guide walks IAM policy evaluation and encryption with worked examples, and the 8-week plan gives it a full week.
How This Shows Up on the Exam
- An app on EC2 must read from S3 with no stored credentials. (Attach an IAM role to the instance.)
- A user is allowed S3 access by a group policy but still denied. Why? (An explicit Deny elsewhere overrides the Allow.)
- 4,000 corporate employees need AWS console access using existing logins. (Identity federation via SAML, assuming a role, not 4,000 IAM users.)
- Prevent anyone, including account admins, from turning off logging. (An SCP at the Organizations level.)
- Encrypt data at rest with control over key rotation and policy. (Customer-managed KMS key.)
Key Takeaways
- Explicit Deny always wins; access is deny-by-default until an Allow matches
- Prefer roles (temporary credentials) over IAM users with long-lived access keys
- KMS for at-rest encryption and envelope encryption; TLS for in-transit; CloudHSM only for dedicated-HSM compliance
- SCPs cap permissions at the account level; they never grant
- Match threat services to keywords: WAF/Shield/GuardDuty/Macie/CloudTrail
- The winning pattern is least privilege plus defense in depth plus no stored secrets
Continue with high availability and disaster recovery for the Resilience domain, and drill Security scenarios in Preporato's SAA-C03 practice exams.
Sources:
Last updated: July 10, 2026
Ready to Pass the SAA-C03 Exam?
Join thousands who passed with Preporato practice tests
