Courseiva
Design Secure Architectures →mediumMultiple Choice

SAA-C03 Design Secure Architectures Practice Question

A finance application stores invoices in Amazon S3. Security requires that the data be encrypted with a key they control, and they want the ability to disable access quickly if the application is suspected of compromise. Developers do not want to manage encryption in application code. Which solution best meets these requirements?

⚠ Common exam trap

Many exam-takers confuse SSE-S3 with customer-managed keys or think S3 replication provides security controls, but the key distinction is that only SSE-KMS with a customer-managed key gives you both customer-controlled keys and the ability to quickly revoke access without changing application code.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use SSE-KMS with a customer-managed AWS KMS key.

SSE-KMS with a customer-managed AWS KMS key meets the requirements because it allows the finance application to encrypt data at rest using a key that the customer controls, and it provides the ability to quickly disable access by revoking or disabling the KMS key, which immediately blocks any decryption attempts. The developers do not need to manage encryption in application code because encryption is handled server-side by S3 using the KMS key.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use SSE-S3 with the default Amazon-managed key for all uploads.

    Why it's wrong here

    SSE-S3 encrypts each object at rest with a unique data key that is itself protected by an Amazon-managed root key. While this protects against physical compromise of S3 storage, AWS fully controls the key rotation and lifecycle, leaving no ability for the security team to set key policies, issue grants, or audit key usage through CloudTrail. If a suspected compromise occurs, you cannot disable this key to immediately block access—all objects would need to be deleted manually, and any cached copies remain readable. Because the requirement explicitly states the security team must control and revoke keys, the default Amazon-managed key is insufficient.

    When this WOULD be correct

    A question that requires server-side encryption with minimal management overhead and no need for customer key control or quick key disabling, e.g., 'A company wants to encrypt all S3 objects by default with no additional cost or key management burden.'

  • ✓

    Use SSE-KMS with a customer-managed AWS KMS key.

    Why this is correct

    SSE-KMS with a customer-managed KMS key gives the security team explicit control over key policy, grants, auditing, and revocation. The application can upload objects normally while S3 handles encryption and decryption on the service side, so developers do not need custom cryptography code. If compromise is suspected, the key or grants can be disabled to block future access, which is exactly why a customer-managed key is preferable here.

  • ✗

    Encrypt objects on the client side and store the encryption key in the same S3 bucket.

    Why it's wrong here

    Client-side encryption with the key stored in the same S3 bucket completely nullifies the value of encryption, since an attacker with read access to the bucket can retrieve both the ciphertext and the decryption key. This approach also forces the application to manage and synchronize key material in a location that is itself targeted, while developer teams must implement and maintain custom cryptographic code. Storing a key alongside its data is a fundamental security anti-pattern; credentials or keys should reside in a hardened service like AWS KMS or Secrets Manager. This option both fails the key-control requirement and weakens the overall security posture.

    When this WOULD be correct

    This option would be correct if the requirement was that data must be encrypted before it reaches AWS (e.g., for compliance with data sovereignty laws) and the application team is willing to manage encryption logic, but they want to store the key separately (e.g., in AWS Secrets Manager or a different bucket with strict access controls).

  • ✗

    Use Amazon S3 replication to a second bucket in another region.

    Why it's wrong here

    S3 replication duplicates objects across regions for durability and disaster recovery, but it does not alter the encryption mechanism or key management of the source objects. Since replication copies the object as-is, any unencrypted or weakly encrypted data remains that way unless you separately adjust the destination bucket's encryption settings. Moreover, replicating data to a second region actually multiplies copies, making it harder to revoke or secure data in an incident. Replication alone gives the security team no control over encryption keys, so this solution fails the stated requirement.

    When this WOULD be correct

    A question requiring cross-region disaster recovery or compliance with data residency requirements, where the goal is to automatically replicate objects to a bucket in another region for redundancy, without specific encryption control or access revocation needs.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SAA-C03 exam frequently reuses these exact scenarios with slightly different constraints.

✓Use SSE-KMS with a customer-managed AWS KMS key.Correct answer▾

Why this is correct

SSE-KMS with a customer-managed KMS key gives the security team explicit control over key policy, grants, auditing, and revocation. The application can upload objects normally while S3 handles encryption and decryption on the service side, so developers do not need custom cryptography code. If compromise is suspected, the key or grants can be disabled to block future access, which is exactly why a customer-managed key is preferable here.

✗Use SSE-S3 with the default Amazon-managed key for all uploads.Wrong answer — click to see why▾

Why this is wrong here

SSE-S3 uses an AWS-managed key, not a customer-controlled key, so it fails the requirement that the customer controls the encryption key.

★ When this WOULD be the correct answer

A question that requires server-side encryption with minimal management overhead and no need for customer key control or quick key disabling, e.g., 'A company wants to encrypt all S3 objects by default with no additional cost or key management burden.'

Why candidates choose this

Candidates may think SSE-S3 provides encryption and is simple to implement, overlooking the specific requirement for customer-controlled keys and the ability to quickly disable access.

✗Encrypt objects on the client side and store the encryption key in the same S3 bucket.Wrong answer — click to see why▾

Why this is wrong here

Client-side encryption requires managing encryption in application code, which contradicts the requirement that developers do not want to manage encryption in the application. Additionally, storing the encryption key in the same S3 bucket is insecure and violates the principle of separating keys from data.

★ When this WOULD be the correct answer

This option would be correct if the requirement was that data must be encrypted before it reaches AWS (e.g., for compliance with data sovereignty laws) and the application team is willing to manage encryption logic, but they want to store the key separately (e.g., in AWS Secrets Manager or a different bucket with strict access controls).

Why candidates choose this

Candidates may think client-side encryption gives them full control over the key and avoids AWS-managed services, but they overlook the explicit requirement to avoid managing encryption in application code and the security risk of storing keys with data.

✗Use Amazon S3 replication to a second bucket in another region.Wrong answer — click to see why▾

Why this is wrong here

S3 replication does not provide encryption with a customer-controlled key or the ability to quickly disable access; it only copies objects to another bucket, which may still use the same encryption settings.

★ When this WOULD be the correct answer

A question requiring cross-region disaster recovery or compliance with data residency requirements, where the goal is to automatically replicate objects to a bucket in another region for redundancy, without specific encryption control or access revocation needs.

Why candidates choose this

Candidates may think replication adds a layer of security or control, but it does not address encryption key management or rapid access revocation as required.

Analysis generated from the official SAA-C03blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SAA-C03 question from scratch — 935 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.