SAA-C03 Design Secure Architectures Practice Question
A claims portal must ensure that only encrypted EBS volumes can be created in the account. What is the strongest preventive control?
⚠ Common exam trap
Candidates often confuse detective or corrective controls (like tagging or Lambda remediation) with preventive controls, failing to recognize that only an SCP or IAM policy with a deny effect on the CreateVolume action can proactively block the creation of unencrypted volumes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use an SCP that denies ec2:CreateVolume when the encrypted condition is false
Service Control Policies (SCPs) are a preventive control that can deny the ec2:CreateVolume action when the encryption condition is false. This ensures that unencrypted EBS volumes cannot be created at all, enforcing encryption at the point of creation across the entire AWS account or organizational unit.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Tag encrypted volumes after creation
Why it's wrong here
Tags are simply key-value metadata attached to EBS volumes for cost allocation or operational management. Adding an 'Encrypted=true' tag after creation does not change the volume's underlying encryption state and has no effect on the AWS control plane that provisions volumes. Furthermore, a tagging process runs after the resource exists, so an unencrypted volume has already been deployed and could hold sensitive data. This approach gives only illusory compliance, not actual enforcement.
- ✗
Enable VPC Flow Logs
Why it's wrong here
VPC Flow Logs capture IP traffic metadata—source address, destination address, ports, protocol, and packet/byte counts—at the elastic network interface level. They neither inspect nor influence EBS volume APIs, and they cannot detect whether a hidden volume is encrypted. Flow logs are useful for network troubleshooting and security analysis, but they have no mechanism to block or alter volume creation. Therefore, enabling them has no bearing on EBS encryption compliance.
- ✓
Use an SCP that denies ec2:CreateVolume when the encrypted condition is false
Why this is correct
An SCP attached to an organizational unit or account can deny ec2:CreateVolume whenever the ec2:Encrypted request condition is false, preventing the API call from succeeding across all affected accounts. This works at the IAM/Organizations evaluation layer, so the request is rejected before a single unencrypted volume is provisioned. For robust enforcement, the SCP condition should use the Bool operator with ec2:Encrypted set to 'false' to explicitly block noncompliant volume creation. This is a preventive control rather than a detective or corrective one, which is why it is the correct answer.
- ✗
Run a daily Lambda function to encrypt unencrypted volumes
Why it's wrong here
Unencrypted EBS volumes cannot be encrypted in place; Amazon EC2 only supports encryption when creating a new volume from an encrypted snapshot or through a migration process. A daily Lambda job is by definition a corrective and detective control, meaning an unencrypted volume remains accessible for up to 24 hours before the script runs. Additionally, the Lambda function would need to orchestrate snapshotting, encrypted volume creation, and instance attachment, which risks downtime and data loss. This leaves a compliance gap and does not prevent users from creating more unencrypted volumes.
Go deeper
Related to this question
About these practice questions
This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.