Courseiva

SAA-C03 Design Secure Architectures Practice Question

A financial services company stores sensitive customer statements in an Amazon S3 bucket. The security team requires that all data be encrypted at rest using keys that the company manages and rotates on its own schedule. The company also needs an audit trail of every time a key was used to encrypt or decrypt data. Which solution meets these requirements?

⚠ Common exam trap

Many exam-takers confuse encryption at rest with key usage auditing; only KMS-backed encryption with customer managed keys provides a CloudTrail record of each key operation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use S3 server-side encryption with AWS KMS customer managed keys (SSE-KMS).

SSE-KMS with customer managed keys gives the company ownership of the key material lifecycle, including rotation, and integrates with AWS CloudTrail so every Encrypt and Decrypt call is logged. This combination directly addresses both the control and audit requirements. Other S3 encryption options either do not allow customer-managed rotation or do not produce a usable key usage audit trail.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use S3 server-side encryption with AWS KMS customer managed keys (SSE-KMS).

    Why this is correct

    SSE-KMS with customer managed keys allows the company to create and rotate keys on its own schedule. AWS KMS records every use of the key in AWS CloudTrail, providing the required audit trail. This satisfies both the control over rotation and the need to log each cryptographic operation.

  • ✗

    Enable default encryption on the bucket using Amazon S3 managed keys and enable versioning.

    Why it's wrong here

    Default encryption with S3 managed keys still uses keys controlled by AWS, not the company, and rotation is handled by AWS. Versioning protects against accidental deletion but does not provide key management control or a key usage audit trail. This does not meet the stated requirements.

  • ✗

    Use S3 server-side encryption with Amazon S3 managed keys (SSE-S3).

    Why it's wrong here

    SSE-S3 uses keys that AWS manages and rotates automatically, and the company has no control over the rotation schedule. Additionally, SSE-S3 does not provide a separate audit trail of individual key usage through a key management service. This does not meet the requirement for customer-managed keys with auditability.

  • ✗

    Use S3 server-side encryption with customer-provided keys (SSE-C).

    Why it's wrong here

    SSE-C requires the company to provide the encryption key with every request, and AWS does not store the key. While the company manages the key, there is no AWS service audit trail of key usage because the key never resides in AWS. This fails the requirement for an audit trail of key usage.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.