Design Secure Architectures Practice Question

Question

For a cross-account deployment, an architect is reviewing IAM least privilege requirement set 17. Which design choice best fits the requirement while following AWS architectural best practices?

Answer choices

  1. A. Grant only the actions and resources required by a role.
  2. B. Place all components on a single large instance to simplify troubleshooting.
  3. C. Use long-lived access keys in application configuration so services can call AWS APIs directly.
  4. D. Disable monitoring until the workload reaches steady production traffic.

Correct Answer

A. Grant only the actions and resources required by a role.

Explanation

The best answer applies IAM least privilege: grant only the actions and resources required by a role. The other options increase operational risk, weaken security, or remove observability that an AWS Solutions Architect should preserve.

Question details

  • Difficulty: easy
  • Domain: Design Secure Architectures
  • Objective: IAM least privilege

Practice more

Start Design Secure Architectures practice

Back to Design Secure Architectures