SAA-C03 Design Secure Architectures Practice Question
A company stores sensitive documents in an Amazon S3 bucket and must ensure that every object is encrypted at rest with keys that the company can audit and rotate. The security team also wants to detect and automatically respond if anyone attempts to disable encryption on the bucket. Which approach best satisfies these goals?
⚠ Common exam trap
The trap here is equating encryption at rest with compliance, when the scenario also demands auditability, key rotation, and automated response to configuration drift.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable default encryption with SSE-KMS using a customer managed key, block public access, and use AWS CloudTrail with an Amazon EventBridge rule and AWS Lambda to remediate unauthorized changes.
The requirements combine key control with automated detection and response. Customer managed KMS keys provide auditable, rotatable encryption, while CloudTrail captures the configuration API calls and EventBridge plus Lambda turn those events into automatic remediation. Block Public Access is a useful hardening step but is not the mechanism that detects an encryption change.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable default encryption with SSE-S3 and turn on S3 server access logging to a separate bucket.
Why it's wrong here
SSE-S3 uses keys fully managed by AWS, so the company cannot audit or rotate them, failing the key-control requirement. Server access logging records requests after the fact but does not detect or automatically respond to a policy change that disables encryption, so the response objective is also unmet.
- ✗
Enable default encryption with SSE-KMS using an AWS managed key and enable S3 Block Public Access at the account level.
Why it's wrong here
An AWS managed key cannot be rotated on demand by the company and its policy is fixed, so the audit and rotation goals are not met. Block Public Access protects against public exposure but does nothing to detect or respond to someone changing the bucket's encryption settings, leaving the response requirement unaddressed.
- ✓
Enable default encryption with SSE-KMS using a customer managed key, block public access, and use AWS CloudTrail with an Amazon EventBridge rule and AWS Lambda to remediate unauthorized changes.
Why this is correct
SSE-KMS with a customer managed key gives auditable, rotatable encryption under company control. CloudTrail records bucket configuration API calls, and EventBridge can match those events and invoke a Lambda function to revert or alert, providing automated detection and response. This combination directly addresses both the encryption and monitoring requirements.
- ✗
Require client-side encryption before upload and enable versioning on the bucket to preserve prior object states.
Why it's wrong here
Client-side encryption puts key management entirely on the application, which can be audited but is not the S3 default encryption control the scenario implies and adds significant operational burden. Versioning protects object data from overwrite or deletion but does not detect or automatically respond to a change in bucket encryption configuration.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.