SAA-C03 Design Secure Architectures Practice Question
A financial services company stores sensitive customer statements in an Amazon S3 bucket. The security team requires that all data be encrypted at rest using keys that the company manages and rotates on its own schedule. The company also needs an audit trail of every time a key was used to encrypt or decrypt data. Which solution meets these requirements?
⚠ Common exam trap
Many exam-takers confuse encryption at rest with key usage auditing; only KMS-backed encryption with customer managed keys provides a CloudTrail record of each key operation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use S3 server-side encryption with AWS KMS customer managed keys (SSE-KMS).
SSE-KMS with customer managed keys gives the company ownership of the key material lifecycle, including rotation, and integrates with AWS CloudTrail so every Encrypt and Decrypt call is logged. This combination directly addresses both the control and audit requirements. Other S3 encryption options either do not allow customer-managed rotation or do not produce a usable key usage audit trail.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use S3 server-side encryption with AWS KMS customer managed keys (SSE-KMS).
Why this is correct
SSE-KMS with customer managed keys allows the company to create and rotate keys on its own schedule. AWS KMS records every use of the key in AWS CloudTrail, providing the required audit trail. This satisfies both the control over rotation and the need to log each cryptographic operation.
- ✗
Enable default encryption on the bucket using Amazon S3 managed keys and enable versioning.
Why it's wrong here
Default encryption with S3 managed keys still uses keys controlled by AWS, not the company, and rotation is handled by AWS. Versioning protects against accidental deletion but does not provide key management control or a key usage audit trail. This does not meet the stated requirements.
- ✗
Use S3 server-side encryption with Amazon S3 managed keys (SSE-S3).
Why it's wrong here
SSE-S3 uses keys that AWS manages and rotates automatically, and the company has no control over the rotation schedule. Additionally, SSE-S3 does not provide a separate audit trail of individual key usage through a key management service. This does not meet the requirement for customer-managed keys with auditability.
- ✗
Use S3 server-side encryption with customer-provided keys (SSE-C).
Why it's wrong here
SSE-C requires the company to provide the encryption key with every request, and AWS does not store the key. While the company manages the key, there is no AWS service audit trail of key usage because the key never resides in AWS. This fails the requirement for an audit trail of key usage.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.