SAA-C03 Design Secure Architectures Practice Question
A healthcare company stores patient records in an Amazon S3 bucket. Compliance requires that every object be encrypted with a key that the company rotates on its own schedule, that key usage be logged separately from S3 data events, and that a specific group of IAM principals be the only identities allowed to use the key for cryptographic operations. The security team has already created a symmetric AWS KMS customer managed key. Which combination of actions should the team take to meet these requirements?
⚠ Common exam trap
The trap here is assuming that enabling any server-side encryption on the bucket automatically gives you control over rotation and key-level access, when only a customer managed KMS key provides that governance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the bucket to use SSE-KMS with the customer managed key, and edit the key policy so only the designated principals have kms:Decrypt, kms:GenerateDataKey, and related permissions.
A customer managed key in AWS KMS is the only option that gives the organization control over rotation, produces dedicated CloudTrail logging of key usage, and enforces who may perform cryptographic operations through the key policy. Pairing it with SSE-KMS on the bucket applies that governance to every object written to the bucket without application changes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable SSE-C on the bucket and distribute the raw encryption key to the application team so they pass it in the x-amz-server-side-encryption-customer-key header with each request.
Why it's wrong here
SSE-C requires the customer to supply and manage the key material on every request, and AWS does not store or rotate that key. There is no AWS KMS key policy to restrict identities, and key usage is not logged as a KMS operation, so the rotation, audit, and access-control requirements cannot be satisfied with this approach.
- ✗
Enable S3 default encryption with SSE-S3 (AES-256) on the bucket, and rely on the AWS managed key aws/s3 for rotation and audit logging.
Why it's wrong here
SSE-S3 uses AES-256 keys fully managed by Amazon S3, so the company cannot control the rotation schedule, cannot see key usage in AWS CloudTrail as a separate key, and cannot restrict the key to a specific set of IAM principals. This fails the requirement that the organization own and govern the key, so it does not satisfy the compliance controls described.
- ✗
Use client-side encryption with the AWS Encryption SDK, store the data key in AWS Secrets Manager, and let any principal in the account retrieve it when needed.
Why it's wrong here
Client-side encryption moves key management into the application and does not provide a KMS key policy that limits cryptographic operations to a single group of principals. Allowing any principal in the account to retrieve the data key from Secrets Manager is broader than the required access, and KMS key usage would not be logged for the stored objects.
- ✓
Configure the bucket to use SSE-KMS with the customer managed key, and edit the key policy so only the designated principals have kms:Decrypt, kms:GenerateDataKey, and related permissions.
Why this is correct
SSE-KMS with a customer managed key lets the company define its own rotation schedule, produces separate AWS CloudTrail entries for the KMS key, and enforces access through the key policy. Restricting the key policy to the designated IAM principals ensures only those identities can perform cryptographic operations, which directly meets the stated compliance requirements.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
One of 935 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.