AWS Certified DevOps Engineer – ProfessionalSecurity and ComplianceHard

A software company is developing a new SaaS application that requires strong isolation between customer environments. Each customer's data and compute resources must be logically separated to prevent cross-tenant data leakage. The DevOps team needs to design an architecture that provides this isolation while maintaining operational efficiency. Which approach BEST achieves logical isolation and scalability for multi-tenant SaaS applications on AWS?

  1. ADeploy all customer resources into a single AWS account using separate VPCs for each customer.
  2. BUse separate AWS accounts for each customer, managed by AWS Organizations.
  3. CImplement resource-based policies and strong IAM roles within a single VPC for all customers.
  4. DUtilize separate subnets within a single VPC for each customer and apply Network ACLs.
Show answer & explanation

Correct answer: B. Use separate AWS accounts for each customer, managed by AWS Organizations.

Using separate AWS accounts for each customer provides the strongest logical isolation boundary available in AWS. Account boundaries inherently prevent cross-tenant data leakage by default and simplify access control. Managing these accounts with AWS Organizations allows for centralized governance and billing, maintaining operational efficiency while maximizing isolation.

Why the other options are wrong

  • A. While separate VPCs offer network isolation, they still share the same AWS account boundary, meaning IAM policies and potential misconfigurations could bridge the gap more easily than separate accounts.
  • C. Relying solely on IAM and resource policies within a single VPC significantly increases the blast radius of a misconfiguration or breach and requires complex policy management to achieve strong isolation.
  • D. Separate subnets within a single VPC offer network segmentation but do not provide the same level of logical isolation as separate accounts or even separate VPCs, leaving other AWS services (e.g., IAM) as potential shared attack surfaces.

Multi-Tenant Isolation Strategies

Methods used in SaaS architectures to ensure that different customers (tenants) cannot access or interfere with each other's data or resources.

  • Crucial for security, privacy, and compliance.
  • Ranges from shared infrastructure with logical separation to dedicated infrastructure.
  • AWS accounts provide the strongest logical isolation boundary.

Memory trick: Each customer gets their own 'house' (account) for ultimate privacy.

More Security and Compliance questions