SAA-C03 Design Secure Architectures Practice Question
A healthcare company stores patient imaging studies in an Amazon S3 bucket encrypted with SSE-KMS using a customer managed key. A security audit reveals that a former employee's IAM user still has s3:GetObject permissions on the bucket. The company wants to ensure the former employee can no longer decrypt any objects, even if they somehow regain S3 access, without affecting other users or applications. What should a security engineer do?
⚠ Common exam trap
The trap here is assuming that removing S3 permissions alone is sufficient, when SSE-KMS decryption also requires kms:Decrypt authorization on the key.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Update the KMS key policy to explicitly deny the former employee's IAM user the kms:Decrypt action.
With SSE-KMS, decryption requires both S3 read permission and kms:Decrypt on the customer managed key. Adding an explicit deny for the former employee in the KMS key policy ensures they cannot decrypt objects even if S3 access is accidentally restored, while leaving other principals unaffected. Bucket-level or access key actions do not remove the cryptographic capability, and disabling the key would break access for everyone.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable the customer managed KMS key used for the bucket encryption.
Why it's wrong here
Disabling the KMS key would prevent all users and applications from decrypting any objects in the bucket, causing a broad outage. The requirement is to revoke access only for the former employee while preserving access for authorized users. Disabling the key is a denial-of-service action against the entire data set, not a targeted revocation of one principal's access.
- ✗
Add a bucket policy that denies s3:GetObject to the former employee's IAM user ARN.
Why it's wrong here
A bucket policy deny on s3:GetObject blocks the S3 API call but does not address the underlying KMS key. If the former employee obtains access through another path, such as a different bucket or a pre-signed URL, or if the bucket policy is later modified, they could still decrypt objects if they retain kms:Decrypt. The requirement specifically targets decryption capability, so the KMS key policy is the correct control point.
- ✗
Enable S3 Block Public Access on the bucket and rotate the IAM user's access keys.
Why it's wrong here
Block Public Access only prevents public ACLs and policies; it does not affect an authenticated IAM user's access. Rotating the former employee's access keys is useful only if they still hold those keys, but the goal is to prevent decryption even if they regain access through any credentials. Neither action removes the kms:Decrypt capability tied to the IAM user identity.
- ✓
Update the KMS key policy to explicitly deny the former employee's IAM user the kms:Decrypt action.
Why this is correct
SSE-KMS requires the caller to have kms:Decrypt permission on the customer managed key in addition to s3:GetObject. Adding an explicit deny for the former employee in the key policy guarantees they cannot decrypt objects even if IAM or bucket policies later grant S3 access, because an explicit deny in the key policy overrides any allow. This achieves targeted revocation without impacting other principals.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.