AWSSAA-C03IAMSecurityKMSSolutions Architect

AWS IAM & Security Architectures for SAA-C03 (2026)

Preporato TeamSeptember 4, 202614 min readSAA-C03
AWS IAM & Security Architectures for SAA-C03 (2026)

Security is the largest SAA-C03 domain at 30%, roughly one question in three, and it is the one where the "best" answer is least negotiable. Performance and cost questions often have several workable options ranked by degree; security questions have a correct answer and several that leave a hole. This guide covers IAM, encryption, and network security to the depth the exam demands.

For where this sits in the whole exam, see the domains breakdown; for the network-security half, pair it with the VPC guide.

Find out where you stand first

Take the free SAA-C03 sample questions cold (no signup, real exam style), then read on with your gaps in mind. When you are ready for full rehearsal, Preporato's SAA-C03 practice tests include 6 full-length exams (401 questions in total, domain-proportional, every answer explained) for a one-time $19.99 with lifetime access.

IAM: The Core of the Domain

The four identity types. Users (long-lived, a person or app), groups (a bucket of users for shared permissions), roles (temporary credentials assumed by a principal), and policies (JSON documents granting or denying permissions). The exam's strong preference: roles over users with access keys wherever possible, because roles issue short-lived credentials and remove the standing secret that leaks.

Policy evaluation logic, tested directly and often:

  1. Start from an implicit deny (nothing is allowed by default).
  2. An explicit Allow in any applicable policy grants access.
  3. An explicit Deny anywhere overrides any Allow.

So the rule to memorize: explicit deny always wins. A question where a user has an Allow from a group but a Deny from an SCP or a boundary policy resolves to denied. This is the single most-tested IAM mechanic.

Roles for the three big use cases:

  • EC2 instance profile: an app on EC2 needs to call S3. Attach a role to the instance, never bake keys into the AMI. The "app needs AWS access without stored credentials" answer is always an instance role.
  • Cross-account access: account A assumes a role in account B. The clean way to grant another account (or a vendor) scoped access without sharing credentials.
  • Identity federation: corporate users sign in with existing identity (SAML, or web identity via Cognito) and assume a role. The "let 5,000 corporate users use AWS without creating 5,000 IAM users" answer.

Guardrails above IAM. Service Control Policies (SCPs) in AWS Organizations set the maximum permissions an account can have; they do not grant anything, they cap. Permissions boundaries do the same for an individual principal. A scenario about "prevent any user in this account from disabling CloudTrail, even admins" wants an SCP.

Preparing for SAA-C03? Practice with 390+ exam questions

Encryption: At Rest and In Transit

KMS (Key Management Service) is the center of gravity. It manages encryption keys and performs envelope encryption: KMS holds the key that encrypts your data keys, so the small master key stays in KMS while bulk data is encrypted locally with data keys. Know:

  • AWS-managed keys vs customer-managed keys (CMK): choose CMK when you need key rotation control, custom key policies, or cross-account key use.
  • Encryption at rest is a toggle-plus-key on EBS, S3, RDS, and most storage. Enable it; "data must be encrypted at rest" is a KMS answer.
  • Encryption in transit is TLS. "Data must be encrypted in transit" wants HTTPS/TLS, ACM-issued certificates on load balancers.
  • CloudHSM is the answer only when the stem demands a dedicated, single-tenant hardware module or specific compliance (FIPS 140-2 Level 3) that managed KMS does not meet.

Secrets belong in Secrets Manager (automatic rotation, the answer when rotation is mentioned) or SSM Parameter Store (cheaper, no built-in rotation), never in code, environment files baked into images, or plaintext user data.

Network and Threat Security

The protective services, and the exact job each does:

Security services by job

JobService
Filter malicious L7 web traffic (SQLi, XSS)AWS WAF
Absorb DDoS attacksAWS Shield (Standard free; Advanced for large-scale)
Detect threats from logs and traffic (ML)Amazon GuardDuty
Aggregate security posture and findingsAWS Security Hub
Discover and classify sensitive data in S3Amazon Macie
Record all API calls for auditAWS CloudTrail
Assess resource configuration complianceAWS Config
Automated vulnerability scanningAmazon Inspector

The tell-tale keywords: "SQL injection / cross-site scripting" -> WAF; "DDoS" -> Shield; "detect unusual API activity or compromised instances" -> GuardDuty; "find credit-card numbers or PII in a bucket" -> Macie; "who did what, when, for audit" -> CloudTrail.

Master These Concepts with Practice

Our SAA-C03 practice bundle includes:

  • 6 full practice exams (390+ questions)
  • Detailed explanations for every answer
  • Domain-by-domain performance tracking

30-day money-back guarantee

The "Most Secure" Architecture Patterns

Security-domain scenario answers cluster around a few principles the exam rewards every time:

  • Least privilege. The correct answer grants the minimum permissions for the task, not * on a resource. An option with broad admin access is almost always wrong.
  • Defense in depth. Layer controls: security groups and NACLs, encryption and IAM, private subnets and least-privilege roles.
  • No hardcoded credentials. Roles, Secrets Manager, and instance profiles beat any answer that stores a key.
  • Private by default. Databases in private subnets, S3 buckets not public, endpoints instead of internet paths.
  • Encrypt everywhere it is cheap to. At rest with KMS, in transit with TLS.

Study the domain with weighted depth

Because Security is 30%, it deserves a disproportionate share of study time. The SAA-C03 study guide walks IAM policy evaluation and encryption with worked examples, and the 8-week plan gives it a full week.

How This Shows Up on the Exam

  • An app on EC2 must read from S3 with no stored credentials. (Attach an IAM role to the instance.)
  • A user is allowed S3 access by a group policy but still denied. Why? (An explicit Deny elsewhere overrides the Allow.)
  • 4,000 corporate employees need AWS console access using existing logins. (Identity federation via SAML, assuming a role, not 4,000 IAM users.)
  • Prevent anyone, including account admins, from turning off logging. (An SCP at the Organizations level.)
  • Encrypt data at rest with control over key rotation and policy. (Customer-managed KMS key.)

Key Takeaways

  • Explicit Deny always wins; access is deny-by-default until an Allow matches
  • Prefer roles (temporary credentials) over IAM users with long-lived access keys
  • KMS for at-rest encryption and envelope encryption; TLS for in-transit; CloudHSM only for dedicated-HSM compliance
  • SCPs cap permissions at the account level; they never grant
  • Match threat services to keywords: WAF/Shield/GuardDuty/Macie/CloudTrail
  • The winning pattern is least privilege plus defense in depth plus no stored secrets

Continue with high availability and disaster recovery for the Resilience domain, and drill Security scenarios in Preporato's SAA-C03 practice exams.


Sources:

Last updated: July 10, 2026

Ready to Pass the SAA-C03 Exam?

Join thousands who passed with Preporato practice tests

Instant access30-day guaranteeUpdated monthly
SAA-C03
6 Practice Exams
Detailed Explanations
Performance Analytics
Get Full Access - $19.99See what's included →

SAA-C03 · 6 practice exams

$19.99one-time

Get full access