SAA-C03 Design Secure Architectures Practice Question
A financial analytics team stores sensitive customer data in an Amazon S3 bucket. The bucket uses SSE-KMS with a customer-managed key. Analysts access objects using an IAM role attached to an EC2 instance in a private subnet. The role has s3:GetObject permission on the bucket. However, analysts report AccessDenied errors when downloading objects. The KMS key policy currently grants full access to the account root user only. What is the most likely cause of the AccessDenied errors?
⚠ Common exam trap
The trap here is assuming that s3:GetObject alone is sufficient for reading SSE-KMS encrypted objects, overlooking the separate kms:Decrypt requirement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The IAM role lacks the kms:Decrypt permission on the customer-managed KMS key used for SSE-KMS.
Objects encrypted with SSE-KMS using a customer-managed key require the caller to have kms:Decrypt permission on that key. The EC2 role has s3:GetObject but no KMS permissions, and the key policy grants access only to the account root. S3 evaluates both the S3 and KMS permissions when serving the object. Without kms:Decrypt, S3 returns AccessDenied even though the S3 permission is present.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The IAM role lacks the kms:Decrypt permission on the customer-managed KMS key used for SSE-KMS.
Why this is correct
With SSE-KMS using a customer-managed key, the caller must have both s3:GetObject and kms:Decrypt on the key. The KMS key policy grants only the account root, so the EC2 role has no kms:Decrypt permission. Without it, S3 cannot decrypt the object for the caller, resulting in AccessDenied. Adding kms:Decrypt to the role or key policy resolves the issue.
- ✗
The S3 bucket is configured with default encryption using SSE-S3, which conflicts with SSE-KMS and causes decryption failures.
Why it's wrong here
SSE-S3 and SSE-KMS are both valid encryption options for S3. If the bucket default were SSE-S3, objects would use an S3-managed key and no KMS permissions would be needed. The scenario explicitly states SSE-KMS with a customer-managed key, so the conflict described does not exist. The failure is due to missing kms:Decrypt permission.
- ✗
The S3 bucket policy does not explicitly allow the IAM role to perform s3:GetObject.
Why it's wrong here
The scenario states the IAM role already has s3:GetObject permission on the bucket. An explicit bucket policy is not required for same-account access when the IAM identity policy allows the action. The AccessDenied error stems from KMS key permissions, not S3 bucket policy. Adding a bucket policy would not resolve the missing kms:Decrypt permission on the customer-managed key.
- ✗
The EC2 instance's security group does not allow outbound HTTPS traffic to the AWS KMS endpoint.
Why it's wrong here
S3 handles the KMS decryption on behalf of the caller; the EC2 instance does not call KMS directly. Even if the instance cannot reach KMS, S3 performs the decrypt operation server-side. The AccessDenied error indicates an authorization failure, not a network connectivity issue. Security group rules for outbound HTTPS would not change the KMS authorization outcome.
Visual reference
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.