SAA-C03 Design Secure Architectures Practice Question
A company is hosting a sensitive web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The compliance team requires that all data at rest must be encrypted using keys that are rotated annually, and all access to these keys must be logged for auditing purposes. Which solution meets these requirements with the least administrative effort?
⚠ Common exam trap
SAA-C03 often tests the confusion between S3 encryption (SSE-S3, SSE-KMS) and EBS encryption — candidates who pick SSE-S3 for EBS volumes miss that SSE-S3 is an S3-only feature and EBS uses KMS directly.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Encrypt the EC2 EBS volumes using AWS KMS with automatic key rotation enabled.
AWS KMS with automatic key rotation enabled on the EBS encryption key satisfies annual rotation, and KMS logs every key operation to CloudTrail for auditing. EBS encryption at rest is configured at the volume level using a KMS CMK, and enabling rotation is a single checkbox or API call — the least administrative effort. CloudHSM and third-party tools require manual rotation and more operational overhead.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use AWS CloudHSM to manage encryption keys and manually rotate them every year.
Why it's wrong here
CloudHSM provides high-security hardware modules but requires significant administrative effort to manage the cluster, perform backups, and handle manual key rotation. This solution does not meet the requirement of minimizing administrative effort compared to using the fully managed AWS Key Management Service which automates these tasks.
- ✓
Encrypt the EC2 EBS volumes using AWS KMS with automatic key rotation enabled.
Why this is correct
AWS KMS allows for the creation of customer managed keys that support automatic annual rotation. Once enabled, AWS handles the rotation of the backing key material without requiring changes to the application or EBS configuration. This integrates natively with CloudTrail for auditing, making it the most efficient solution available.
- ✗
Implement a third-party encryption tool on the EC2 instances and store keys in an S3 bucket.
Why it's wrong here
Third-party tools often introduce additional complexity and management overhead, such as maintaining the software and securing the S3 bucket where keys are stored. This approach lacks the seamless integration with AWS services and automated rotation features provided by KMS, leading to higher operational risks and administrative burdens.
- ✗
Use Amazon S3 SSE-S3 to encrypt the EBS volumes and monitor access via VPC Flow Logs.
Why it's wrong here
S3 Server-Side Encryption with S3-managed keys (SSE-S3) is specifically designed for objects stored within Amazon S3 and cannot be directly applied to EC2 EBS volumes. Furthermore, VPC Flow Logs capture network traffic information rather than the API-level audit logs required to track encryption key usage effectively.
About these practice questions
Courseiva writes every SAA-C03 question from scratch — 149 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.