AWS Certified Solutions Architect – Associate (SAA-C03)Design Secure ArchitecturesEasy

A software development company uses AWS CodeCommit for source code management. They need to ensure that only authorized developers can push code to specific repositories and that all pushes are authenticated using strong credentials. Which combination of AWS services and features should be used?

  1. AAWS SSO for user authentication, HTTPS Git credentials, and IAM policies.
  2. BIAM roles for EC2 instances, Git credentials for CodeCommit, and branch protections.
  3. CIAM users with Git credentials for CodeCommit and IAM policies attached to users or groups.
  4. DIAM users with SSH keys configured for CodeCommit and repository policies.
Show answer & explanation

Correct answer: C. IAM users with Git credentials for CodeCommit and IAM policies attached to users or groups.

IAM users with Git credentials (either HTTPS or SSH) provide the necessary authentication for CodeCommit. IAM policies attached to these users or their groups then define specific permissions, such as allowing pushes to certain repositories, ensuring both strong authentication and authorization.

Why the other options are wrong

  • A. AWS SSO can be used for centralized identity, but the core mechanism for CodeCommit authentication for individual developers is still Git credentials, and IAM policies are essential for authorization. This option is missing the direct link to Git credentials for the push operation.
  • B. IAM roles for EC2 instances are for applications running on EC2, not typically for individual developer access to CodeCommit. Git credentials are correct, but branch protections are a separate feature for workflow, not primary authentication/authorization.
  • D. SSH keys are one method for CodeCommit authentication, but relying solely on repository policies might not be as flexible or scalable as IAM policies attached to users/groups for fine-grained control.

CodeCommit Access Control

AWS CodeCommit uses IAM users with Git credentials (HTTPS or SSH) for authentication and IAM policies for authorization to control access to repositories.

  • IAM users manage developer identities.
  • Git credentials (HTTPS or SSH) authenticate to CodeCommit.
  • IAM policies define granular permissions (e.g., push, pull).
  • Policies can be attached to users or groups.

Memory trick: IAM: Identify And Manage Code

More Design Secure Architectures questions