Courseiva

SAA-C03 Design Secure Architectures Practice Question

A claims portal must ensure that only encrypted EBS volumes can be created in the account. What is the strongest preventive control?

⚠ Common exam trap

Candidates often confuse detective or corrective controls (like tagging or Lambda remediation) with preventive controls, failing to recognize that only an SCP or IAM policy with a deny effect on the CreateVolume action can proactively block the creation of unencrypted volumes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use an SCP that denies ec2:CreateVolume when the encrypted condition is false

Service Control Policies (SCPs) are a preventive control that can deny the ec2:CreateVolume action when the encryption condition is false. This ensures that unencrypted EBS volumes cannot be created at all, enforcing encryption at the point of creation across the entire AWS account or organizational unit.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Tag encrypted volumes after creation

    Why it's wrong here

    Tags are simply key-value metadata attached to EBS volumes for cost allocation or operational management. Adding an 'Encrypted=true' tag after creation does not change the volume's underlying encryption state and has no effect on the AWS control plane that provisions volumes. Furthermore, a tagging process runs after the resource exists, so an unencrypted volume has already been deployed and could hold sensitive data. This approach gives only illusory compliance, not actual enforcement.

  • ✗

    Enable VPC Flow Logs

    Why it's wrong here

    VPC Flow Logs capture IP traffic metadata—source address, destination address, ports, protocol, and packet/byte counts—at the elastic network interface level. They neither inspect nor influence EBS volume APIs, and they cannot detect whether a hidden volume is encrypted. Flow logs are useful for network troubleshooting and security analysis, but they have no mechanism to block or alter volume creation. Therefore, enabling them has no bearing on EBS encryption compliance.

  • ✓

    Use an SCP that denies ec2:CreateVolume when the encrypted condition is false

    Why this is correct

    An SCP attached to an organizational unit or account can deny ec2:CreateVolume whenever the ec2:Encrypted request condition is false, preventing the API call from succeeding across all affected accounts. This works at the IAM/Organizations evaluation layer, so the request is rejected before a single unencrypted volume is provisioned. For robust enforcement, the SCP condition should use the Bool operator with ec2:Encrypted set to 'false' to explicitly block noncompliant volume creation. This is a preventive control rather than a detective or corrective one, which is why it is the correct answer.

  • ✗

    Run a daily Lambda function to encrypt unencrypted volumes

    Why it's wrong here

    Unencrypted EBS volumes cannot be encrypted in place; Amazon EC2 only supports encryption when creating a new volume from an encrypted snapshot or through a migration process. A daily Lambda job is by definition a corrective and detective control, meaning an unencrypted volume remains accessible for up to 24 hours before the script runs. Additionally, the Lambda function would need to orchestrate snapshotting, encrypted volume creation, and instance attachment, which risks downtime and data loss. This leaves a compliance gap and does not prevent users from creating more unencrypted volumes.

About these practice questions

This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.