SAA-C03 Design Secure Architectures Practice Question
A company is migrating a web application to AWS and needs to ensure that all data stored in Amazon S3 is encrypted at rest using keys managed by the company. The company must be able to rotate these keys annually and maintain full control over key access policies. Which solution meets these requirements?
⚠ Common exam trap
SAA-C03 often tests the distinction between SSE-S3, SSE-KMS with AWS Managed Keys, and SSE-KMS with Customer Managed Keys — candidates who pick AWS Managed Keys miss that only CMKs allow customer-controlled rotation and key policies.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use AWS KMS with Customer Managed Keys.
AWS KMS Customer Managed Keys (CMKs) give the company full control over the key policy, allow annual rotation to be enabled, and support auditing via CloudTrail. SSE-S3 uses AWS-owned keys the customer cannot manage or rotate, and AWS Managed Keys have rotation controlled by AWS (every three years) with policies the customer cannot edit. Uploading a raw master key to S3 is not a supported KMS pattern.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable S3 Managed Keys (SSE-S3) for all buckets.
Why it's wrong here
SSE-S3 uses keys managed entirely by AWS. The customer cannot rotate these keys manually, nor can they define custom key policies to control access. This approach fails to meet the requirement for the customer to maintain full control over key management and rotation schedules as requested in the scenario.
- ✗
Use AWS KMS with AWS Managed Keys.
Why it's wrong here
AWS Managed Keys are automatically managed by AWS services on behalf of the user. While they provide encryption, the customer cannot modify the key policy or manually control the rotation cycle. This option does not provide the administrative control over cryptographic materials necessary to satisfy the specific security requirements.
- ✓
Use AWS KMS with Customer Managed Keys.
Why this is correct
Customer Managed Keys allow the user to define granular key policies and enforce rotation schedules. This provides the level of control required for compliance and security auditing. By managing the key lifecycle, the company fulfills the requirement for ownership and authority over the encryption process for their S3 stored data.
- ✗
Upload a master key to AWS via the S3 console.
Why it's wrong here
Uploading a master key directly to the S3 console is not a standard or secure method for managing S3 encryption. AWS KMS is the designated service for managing encryption keys. This method does not integrate with AWS Identity and Access Management for policy control or offer automated key rotation features.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
About these practice questions
This SAA-C03 question is part of Courseiva's 149-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.