SAA-C03 Design Secure Architectures Practice Question
A security team must ensure that all data written to a new Amazon S3 bucket is encrypted with a specific customer-managed AWS KMS key, and that any PUT request that does not specify that key is rejected. The team also needs to detect and react if someone attempts to change the bucket policy to remove the restriction. Which combination of actions meets these requirements with the LEAST operational effort?
⚠ Common exam trap
The trap here is treating S3 default encryption as an enforcement mechanism, when it only supplies a key for requests that omit encryption headers.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Attach a bucket policy that denies s3:PutObject when the request lacks the required KMS key condition, enable AWS CloudTrail data events, and create an Amazon EventBridge rule that matches PutBucketPolicy API calls and invokes an AWS Lambda function.
A bucket policy with a Deny effect and the KMS key condition rejects any PUT that does not use the required key, which is the only option that enforces encryption at write time. Pairing CloudTrail data events with an EventBridge rule on the PutBucketPolicy API call provides automated detection and response to policy tampering without managing infrastructure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure an S3 Lifecycle rule to re-encrypt objects with the required KMS key and use AWS Config with the s3-bucket-server-side-encryption-enabled managed rule.
Why it's wrong here
Lifecycle rules transition or expire objects and cannot re-encrypt existing objects with a different KMS key. The AWS Config managed rule reports whether default encryption is enabled but does not prevent an object from being written with a noncompliant key, and it is not an automated remediation for policy tampering.
- ✗
Use an S3 access point with a custom policy that allows only the required key, and enable AWS Shield Advanced on the bucket.
Why it's wrong here
An access point policy can restrict access through that access point, but clients can still use the bucket's own endpoint and bypass the access point policy. AWS Shield Advanced protects against distributed denial-of-service attacks and has no role in enforcing encryption key selection or detecting bucket policy changes.
- ✓
Attach a bucket policy that denies s3:PutObject when the request lacks the required KMS key condition, enable AWS CloudTrail data events, and create an Amazon EventBridge rule that matches PutBucketPolicy API calls and invokes an AWS Lambda function.
Why this is correct
A bucket policy with a Deny on s3:PutObject using the s3:x-amz-server-side-encryption-aws-kms-key-id condition blocks unapproved encryption at the API layer. CloudTrail data events and an EventBridge rule on the PutBucketPolicy management event provide near-real-time detection and an automated response, requiring no servers to maintain.
- ✗
Enable default bucket encryption with the required KMS key and turn on S3 Block Public Access at the account level.
Why it's wrong here
Default encryption applies the key only when a PUT request does not specify encryption parameters; it does not reject requests that explicitly use a different key. Block Public Access prevents public exposure of the bucket but does not enforce which KMS key is used for object encryption, so the stated control objective is unmet.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SAA-C03 question from scratch — 935 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.