Courseiva
Design Secure Architectures →mediumMultiple Select

SAA-C03 Design Secure Architectures Practice Question

An architect is designing a secure storage solution for highly sensitive financial data in S3. Which THREE security controls should be implemented? (Select THREE.)

⚠ Common exam trap

SAA-C03 often tests the shared responsibility model and S3 security best practices, and candidates may incorrectly believe that making a bucket public with IP restrictions is secure, or that broad organizational access is acceptable for sensitive data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable S3 Block Public Access at the account level.

Option A is correct because enabling S3 Block Public Access at the account level applies account-wide guardrails that override bucket policies and ACLs, preventing any bucket or object from being made public—an essential baseline for highly sensitive financial data. Option B is correct because AWS KMS with Customer Managed Keys (CMKs) gives the organization control over the key policy, rotation, and grants, providing encryption at rest with auditable key usage via CloudTrail, which is required for regulated financial data. Option C is correct because bucket policies using the aws:SecureTransport condition (e.g., "aws:SecureTransport": "false" with Deny) enforce HTTPS/TLS for all requests, preventing data in transit from being exposed over plain HTTP. Option D is incorrect because granting all users in the organization full access violates least privilege and would allow unauthorized or accidental modification or exfiltration of sensitive data. Option E is incorrect because storing data in a public bucket exposes it to the internet and directly contradicts the requirement for a secure storage solution.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable S3 Block Public Access at the account level.

    Why this is correct

    Blocking public access acts as a centralized safeguard to prevent accidental exposure of S3 buckets to the public internet. This is a crucial first line of defense, ensuring that no bucket within the account can be made public, regardless of individual bucket policy or IAM configuration errors.

  • ✓

    Use AWS KMS with Customer Managed Keys for encryption at rest.

    Why this is correct

    Customer Managed Keys allow for granular access control and auditability. By using these keys, the company retains control over rotation and policy. This ensures that even if data is stolen, it remains encrypted and unusable without the proper KMS key permissions, fulfilling financial compliance requirements for data protection.

  • ✓

    Use Bucket Policies to enforce HTTPS/TLS access.

    Why this is correct

    Requiring HTTPS ensures that data is encrypted in transit between the client and S3. This protects against man-in-the-middle attacks where data could be intercepted. Enforcing this via bucket policies provides a programmatic guarantee that only secure connections are permitted, which is a standard requirement for financial data security.

  • ✗

    Allow all users in the organization to have full access.

    Why it's wrong here

    Granting universal full access violates the principle of least privilege. Highly sensitive data must be protected with narrow, scoped permissions. Only users with an explicit business need should be allowed access, and this access should be strictly defined using IAM policies and resource-based policies.

  • ✗

    Store data in a public bucket for easier access.

    Why it's wrong here

    Storing sensitive data in a public bucket is a catastrophic security failure that exposes the data to the entire world. Sensitive information should never be public. This practice would immediately fail any security audit and result in a high risk of data exfiltration and severe regulatory consequences.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SAA-C03 question from scratch — 149 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.