SAA-C03 Design Secure Architectures Practice Question
A security team requires that every object uploaded to s3://secure-bucket/uploads/ must be encrypted using SSE-KMS with a specific customer-managed KMS key. Which S3 bucket policy condition approach best enforces this requirement for PutObject requests?
⚠ Common exam trap
A common mix-up: candidates confuse encryption in transit (aws:SecureTransport) with encryption at rest (SSE-KMS), or they mistakenly think that checking the caller's KMS permissions in the bucket policy is sufficient, when in fact the policy must inspect the request headers to enforce the encryption requirement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deny PutObject unless s3:x-amz-server-side-encryption equals "aws:kms" and s3:x-amz-server-side-encryption-aws-kms-key-id equals the required CMK ARN
It uses a Deny effect with the s3:x-amz-server-side-encryption condition key set to 'aws:kms' and the s3:x-amz-server-side-encryption-aws-kms-key-id condition key set to the specific customer-managed KMS key ARN. This ensures that any PutObject request that does not include both the required encryption header and the exact KMS key identifier is denied, enforcing the encryption requirement at the bucket policy level.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Deny PutObject unless s3:x-amz-server-side-encryption equals "aws:kms" and s3:x-amz-server-side-encryption-aws-kms-key-id equals the required CMK ARN
Why this is correct
This enforces the encryption choice at upload time by validating the request headers that specify SSE-KMS and the exact KMS key ID/ARN. Using a Deny condition ensures uploads that do not include the correct SSE-KMS headers (for example, unencrypted uploads or uploads using a different KMS key) are rejected immediately.
- ✗
Allow PutObject only when aws:SecureTransport is true; encryption is then guaranteed automatically
Why it's wrong here
aws:SecureTransport checks that the request was transmitted over HTTPS/TLS, which protects data in transit between the client and S3. It has no bearing on how the object is encrypted at rest; S3 can accept a secure-transport PutObject with no encryption headers, storing the object unencrypted or with default encryption rather than the mandated SSE-KMS CMK. Therefore, this condition alone neither requires SSE-KMS nor verifies the specific KMS key ARN, so it fails to guarantee the required encryption at the object level.
When this WOULD be correct
This would be correct if the question required enforcing encryption in transit for all S3 uploads, e.g., 'Ensure all PutObject requests use HTTPS.' Then a Deny with aws:SecureTransport false would be appropriate.
- ✗
Deny PutObject if the request includes Content-Type other than "application/octet-stream"
Why it's wrong here
Content-Type is a standard HTTP header that describes the MIME type of the payload (e.g., image/png, application/json), not an encryption directive. S3 determines server-side encryption from dedicated headers such as s3:x-amz-server-side-encryption and the related KMS key header, not from Content-Type. A Deny rule on Content-Type would reject legitimate uploads of non-octet-stream types while doing nothing to enforce SSE-KMS; an unencrypted PutObject with Content-Type: application/octet-stream would still succeed, leaving the security requirement unmet.
When this WOULD be correct
If the question required that only binary files (e.g., application/octet-stream) be uploaded to a specific bucket, a Deny policy on other Content-Type values would enforce that rule.
- ✗
Deny PutObject when the caller’s role is not allowed to kms:Decrypt in their IAM policy
Why it's wrong here
kms:Decrypt permissions relate to decrypting objects later (for example, after retrieval or during operations that require decryption). They do not control whether S3 accepts the PutObject request using the required SSE-KMS configuration and CMK at upload time.
When this WOULD be correct
Option D would be correct in a scenario where the requirement is to prevent uploads by users who cannot decrypt objects in the bucket (e.g., to ensure only authorized decryptors can upload). For example: 'A security policy requires that only users with permission to decrypt objects using a specific KMS key can upload to the bucket.'
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SAA-C03 exam frequently reuses these exact scenarios with slightly different constraints.
✓Deny PutObject unless s3:x-amz-server-side-encryption equals "aws:kms" and s3:x-amz-server-side-encryption-aws-kms-key-id equals the required CMK ARNCorrect answer▾
Why this is correct
This enforces the encryption choice at upload time by validating the request headers that specify SSE-KMS and the exact KMS key ID/ARN. Using a Deny condition ensures uploads that do not include the correct SSE-KMS headers (for example, unencrypted uploads or uploads using a different KMS key) are rejected immediately.
✗Allow PutObject only when aws:SecureTransport is true; encryption is then guaranteed automaticallyWrong answer — click to see why▾
Why this is wrong here
This option only enforces SecureTransport (HTTPS), not encryption at rest. It does not require SSE-KMS or a specific KMS key, so objects could be uploaded without server-side encryption or with a different encryption method.
★ When this WOULD be the correct answer
This would be correct if the question required enforcing encryption in transit for all S3 uploads, e.g., 'Ensure all PutObject requests use HTTPS.' Then a Deny with aws:SecureTransport false would be appropriate.
Why candidates choose this
Candidates may confuse encryption in transit (HTTPS) with encryption at rest (SSE), or assume that requiring HTTPS automatically enforces server-side encryption, which is not true.
✗Deny PutObject if the request includes Content-Type other than "application/octet-stream"Wrong answer — click to see why▾
Why this is wrong here
This condition restricts Content-Type, not encryption. The requirement is about SSE-KMS encryption, not the MIME type of the object.
★ When this WOULD be the correct answer
If the question required that only binary files (e.g., application/octet-stream) be uploaded to a specific bucket, a Deny policy on other Content-Type values would enforce that rule.
Why candidates choose this
Candidates may confuse content restrictions with encryption requirements, or think that controlling Content-Type is a way to enforce data format standards that indirectly relate to security.
✗Deny PutObject when the caller’s role is not allowed to kms:Decrypt in their IAM policyWrong answer — click to see why▾
Why this is wrong here
Option D is wrong because the question requires encryption with a specific KMS key, not decryption permissions. Denying PutObject based on the caller's inability to decrypt does not enforce the use of the required KMS key for encryption; it only checks decryption capability, which is irrelevant for uploads.
★ When this WOULD be the correct answer
Option D would be correct in a scenario where the requirement is to prevent uploads by users who cannot decrypt objects in the bucket (e.g., to ensure only authorized decryptors can upload). For example: 'A security policy requires that only users with permission to decrypt objects using a specific KMS key can upload to the bucket.'
Why candidates choose this
Candidates may confuse encryption and decryption permissions, thinking that requiring kms:Decrypt for uploads somehow enforces encryption, or they may assume that KMS key permissions are symmetric for encrypt and decrypt operations.
Analysis generated from the official SAA-C03blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SAA-C03 question from scratch — 935 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.