Courseiva

SAA-C03 Design Secure Architectures Practice Question

A company stores sensitive documents in an Amazon S3 bucket and must ensure that every object is encrypted at rest with keys that the company can audit and rotate. The security team also wants to detect and automatically respond if anyone attempts to disable encryption on the bucket. Which approach best satisfies these goals?

⚠ Common exam trap

The trap here is equating encryption at rest with compliance, when the scenario also demands auditability, key rotation, and automated response to configuration drift.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable default encryption with SSE-KMS using a customer managed key, block public access, and use AWS CloudTrail with an Amazon EventBridge rule and AWS Lambda to remediate unauthorized changes.

The requirements combine key control with automated detection and response. Customer managed KMS keys provide auditable, rotatable encryption, while CloudTrail captures the configuration API calls and EventBridge plus Lambda turn those events into automatic remediation. Block Public Access is a useful hardening step but is not the mechanism that detects an encryption change.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable default encryption with SSE-S3 and turn on S3 server access logging to a separate bucket.

    Why it's wrong here

    SSE-S3 uses keys fully managed by AWS, so the company cannot audit or rotate them, failing the key-control requirement. Server access logging records requests after the fact but does not detect or automatically respond to a policy change that disables encryption, so the response objective is also unmet.

  • ✗

    Enable default encryption with SSE-KMS using an AWS managed key and enable S3 Block Public Access at the account level.

    Why it's wrong here

    An AWS managed key cannot be rotated on demand by the company and its policy is fixed, so the audit and rotation goals are not met. Block Public Access protects against public exposure but does nothing to detect or respond to someone changing the bucket's encryption settings, leaving the response requirement unaddressed.

  • ✓

    Enable default encryption with SSE-KMS using a customer managed key, block public access, and use AWS CloudTrail with an Amazon EventBridge rule and AWS Lambda to remediate unauthorized changes.

    Why this is correct

    SSE-KMS with a customer managed key gives auditable, rotatable encryption under company control. CloudTrail records bucket configuration API calls, and EventBridge can match those events and invoke a Lambda function to revert or alert, providing automated detection and response. This combination directly addresses both the encryption and monitoring requirements.

  • ✗

    Require client-side encryption before upload and enable versioning on the bucket to preserve prior object states.

    Why it's wrong here

    Client-side encryption puts key management entirely on the application, which can be audited but is not the S3 default encryption control the scenario implies and adds significant operational burden. Versioning protects object data from overwrite or deletion but does not detect or automatically respond to a change in bucket encryption configuration.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.