SAA-C03 Design Secure Architectures Practice Question
A media company stores video masters in an Amazon S3 bucket encrypted with a customer managed AWS KMS key. Editors sign in through a corporate identity provider that is federated to AWS IAM Identity Center, and they must be able to download and re-upload objects. The security team wants every editor's read of the key material recorded in CloudTrail with the editor's own identity, and wants to be able to revoke one editor's access without affecting the others. Which configuration meets these requirements?
⚠ Common exam trap
The trap here is assuming that S3 bucket permissions alone control access to SSE-KMS objects, when the KMS key policy must also grant the caller Decrypt and GenerateDataKey or the request fails.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a KMS key policy statement that allows kms:Decrypt and kms:GenerateDataKey to the IAM Identity Center permission set role, and let each editor assume that role with their federated identity.
When objects use SSE-KMS, every download requires kms:Decrypt and every upload requires kms:GenerateDataKey, and those calls appear in CloudTrail tied to the calling principal. Federating editors into a permission set role means the role session carries their identity, giving per-person audit records and per-person revocation by removing the assignment, while the key policy authorizes the shared role.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Generate a data key with kms:GenerateDataKeyWithoutPlaintext once, store it in AWS Secrets Manager, and have each editor retrieve it to encrypt and decrypt objects locally before uploading.
Why it's wrong here
This design bypasses KMS for the actual object operations, so no kms:Decrypt events are logged against the editor identities and CloudTrail cannot attribute reads to a person. Handling raw key material in the client also breaks the KMS security model, and rotating or revoking a single editor would require re-encrypting stored data rather than simply changing an identity assignment.
- ✗
Enable S3 server access logging on the bucket and create a separate IAM user for each editor with an inline policy allowing kms:Decrypt on the key.
Why it's wrong here
S3 server access logs record object-level requests but not the KMS key usage that proves who unwrapped the data key, so the required CloudTrail attribution for key material is missing. Creating long-lived IAM users also contradicts the federated sign-in model already in place and multiplies credentials to manage, rotate, and revoke instead of using the existing permission set.
- ✓
Create a KMS key policy statement that allows kms:Decrypt and kms:GenerateDataKey to the IAM Identity Center permission set role, and let each editor assume that role with their federated identity.
Why this is correct
Because editors assume a permission set role through IAM Identity Center, CloudTrail records each kms:Decrypt and kms:GenerateDataKey call with the role session and the federated user identity, satisfying the audit requirement. Removing a single editor from the permission set assignment in IAM Identity Center removes their ability to assume the role, revoking only that person's access without touching the shared key policy.
- ✗
Attach a bucket policy to the S3 bucket that grants s3:GetObject to the federated principal, and rely on the default aws/s3 AWS managed key for encryption so no KMS permissions are needed.
Why it's wrong here
The default aws/s3 managed key cannot be used for SSE-KMS with a customer managed key, and its usage is not attributable to individual editor identities for per-user revocation. Granting s3:GetObject alone also ignores the kms:Decrypt that SSE-KMS requires, so downloads would fail with AccessDenied on the key rather than succeed with the audit trail the security team wants.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.