nerdexam
Amazon

SOA-C03 · Question #147

A company has a multi-account AWS environment that includes the following: - A central identity account that contains all IAM users and groups - Several member accounts that contain IAM roles A SysOps

Sign in or unlock SOA-C03 to reveal the answer and full explanation for question #147. The question stem and answer options stay visible for context.

Submitted by akirajp· Mar 5, 2026Security and compliance

Question

A company has a multi-account AWS environment that includes the following:

  • A central identity account that contains all IAM users and groups
  • Several member accounts that contain IAM roles

A SysOps administrator must grant permissions for a particular IAM group to assume a role in one of the member accounts. How should the SysOps administrator accomplish this task?

Options

  • AIn the member account, add sts:AssumeRole permissions to the role's policy. In the identity
  • BIn the member account, add the group Amazon Resource Name (ARN) to the role's trust policy.
  • CIn the member account, add the group Amazon Resource Name (ARN) to the role's trust policy.
  • DIn the member account, add the group Amazon Resource Name (ARN) to the role's inline policy.

Unlock SOA-C03 to see the answer

You've previewed enough free SOA-C03 questions. Unlock SOA-C03 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#IAM roles#cross-account access#trust policy#STS AssumeRole
Full SOA-C03 Practice