Courseiva
Design Secure Architectures →mediumMultiple Choice

SAA-C03 Design Secure Architectures Practice Question

A batch process uploads artifacts to an Amazon S3 bucket using multipart uploads. The bucket policy contains a statement that explicitly denies PutObject and CreateMultipartUpload unless the request uses server-side encryption with AWS KMS (SSE-KMS) and includes these request headers/parameters: x-amz-server-side-encryption=aws:kms and x-amz-server-side-encryption-aws-kms-key-id set to a specific CMK. After the process was updated, uploads intermittently fail with AccessDenied errors. Which change is the best way to make uploads succeed while still meeting the bucket policy's encryption requirement?

⚠ Common exam trap

Many exam-takers assume the encryption requirement only applies to the final object or to `PutObject` calls, but the explicit Deny in the bucket policy applies to the `CreateMultipartUpload` API call itself, which must also include the required headers to avoid AccessDenied errors.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Update the uploader so the CreateMultipartUpload request includes SSE-KMS with the required CMK key ID; any separate PutObject uploads should include the same headers.

The bucket policy explicitly denies `PutObject` and `CreateMultipartUpload` unless the request includes both `x-amz-server-side-encryption=aws:kms` and the specific `x-amz-server-side-encryption-aws-kms-key-id` header. The intermittent failures occur because the batch process's `CreateMultipartUpload` request (which initiates the multipart upload) is missing these required headers, causing the explicit Deny to trigger. By ensuring that the `CreateMultipartUpload` request includes SSE-KMS with the correct CMK key ID, and that any subsequent `PutObject` parts also include the same headers, the uploads will satisfy the bucket policy and succeed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Update the IAM role policy to add s3:PutObject permissions for the bucket prefix.

    Why it's wrong here

    Even if IAM allows s3:PutObject, an explicit Deny in an S3 bucket policy still blocks the request. If the required SSE-KMS encryption headers, including the required CMK key ID, are not present, the policy Deny still applies.

  • ✓

    Update the uploader so the CreateMultipartUpload request includes SSE-KMS with the required CMK key ID; any separate PutObject uploads should include the same headers.

    Why this is correct

    For multipart uploads, SSE-KMS is specified on CreateMultipartUpload rather than on individual UploadPart calls. Supplying the required SSE-KMS settings and CMK key ID on the upload initiation request satisfies the bucket policy's condition without weakening the encryption requirement.

  • ✗

    Remove the bucket policy's explicit Deny statement so the IAM permissions control access.

    Why it's wrong here

    Removing the explicit Deny from the bucket policy strips the required encryption enforcement and lets S3 accept uploads that lack the mandated SSE-KMS configuration. Because an explicit Deny in a bucket policy overrides any Allow granted through IAM, deleting that statement does not fix the complaint—it merely disables the security check that is blocking non-compliant requests. The correct action is to update the uploader to include the required encryption parameters, not to remove the policy that enforces them.

  • ✗

    Switch to client-side encryption (SSE-C) because it also encrypts data at rest in S3.

    Why it's wrong here

    SSE-C uses customer-provided keys, not AWS KMS, so the bucket policy conditions that require `s3:x-amz-server-side-encryption: aws:kms` and a permitted `s3:x-amz-server-side-encryption-aws-kms-key-id` cannot be satisfied. When a request uses SSE-C, the KMS-specific condition keys are not set, and the explicit Deny in the bucket policy still evaluates as true, causing the upload to be rejected. Switching to SSE-C does not fulfill the encryption requirements and simply trades one mismatched encryption method for another.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.