nerdexam
Amazon

SAA-C03 · Question #802

A company has hired a vendor to perform an audit. The company needs a solution to allow the vendor to access the company's AWS account to review Amazon CloudWatch Logs events. The solution must use…

The correct answer is B. Create an IAM role in the vendor's account. Create an IAM role in the company's account with the. To allow cross-account access, the company creates an IAM role with the necessary CloudWatch Logs permissions and configures its trust policy to allow the vendor’s IAM role to assume it. This enables the vendor to access the company’s resources securely using their own account

Submitted by fatima_kr· Mar 4, 2026Design Secure Architectures

Question

A company has hired a vendor to perform an audit. The company needs a solution to allow the vendor to access the company’s AWS account to review Amazon CloudWatch Logs events. The solution must use IAM roles for cross-account access. Which solution will meet these requirements?

Options

  • ACreate an IAM role in the company's account. Create an IAM role in the vendor's account with the
  • BCreate an IAM role in the vendor's account. Create an IAM role in the company's account with the
  • CCreate an IAM role in the company's account. Create an IAM role in the vendor's account with the
  • DCreate an IAM role in the vendor's account. Create an IAM role in the company's account with the

How the community answered

(44 responses)
  • B
    93% (41)
  • C
    5% (2)
  • D
    2% (1)

Explanation

To allow cross-account access, the company creates an IAM role with the necessary CloudWatch Logs permissions and configures its trust policy to allow the vendor’s IAM role to assume it. This enables the vendor to access the company’s resources securely using their own account

Community Discussion

No community discussion yet for this question.

Full SAA-C03 Practice