GregLab | Exam Prep

Security, Identity, and Compliance

Core

IAM

Identity, roles, policies, and authorization controls for AWS principals and requests.

Key points

  • Prefer roles and federation with temporary credentials; tightly limit IAM users and long-term keys.
  • Role trust controls who may assume; permission policies control allowed actions; explicit denies and boundaries can further restrict.
  • Least privilege must name required actions, resources, and conditions and be refined from actual use.

Best-known use cases

  • Give workloads role-based access to AWS services.
  • Delegate cross-account access with temporary sessions.

What candidates often confuse it with

  • IAM users are persistent identities; roles provide temporary sessions for workloads/federation.
  • Identity policies grant to principals; supported resource policies grant at resources; SCPs only cap permissions.

Key takeaway

Choose the principal and trust model first, then build least-privilege temporary authorization.

Related services

  • AWS IAM Identity Center
  • AWS Organizations
  • AWS Secrets Manager

Relevant exam tasks

  • D1.1
  • D1.2
  • D1.3

Learn more

Free AWS Certified Solutions Architect - Associate prep

Build focused SAA-C03 quizzes from skill areas, topics, and product references.

Practice with exam-style multiple-choice and multiple-response questions, score breakdowns, explanations, and a compact reference for this lane's official exam domains.

Build a quiz

Exam Weights

Exam snapshot

SAA-C03 at a glance

Category
Associate
Duration
130 minutes
Questions
65 total; 50 scored and 15 unidentified unscored
Formats
Multiple choice and multiple response
Scoring
100–1,000 scaled score; 720 minimum passing score

Quiz builder

Choose your practice set

Mode

Exam fidelity: AWS documents 65 questions in 130 minutes: 50 scored and 15 unidentified unscored, using multiple-choice and multiple-response formats. This site's practice accuracy and readiness do not reproduce AWS's 100–1,000 scaled scoring or identify unscored items. Difficulty labels describe this site's Associate-level scenario complexity, not an AWS-published question rating.

Reference

SAA-C03 topics and reference map

Study links

SAA-C03 resources