SAA-C03 Design Secure Architectures Practice Question
A solutions architect must store application configuration data in AWS Systems Manager Parameter Store. Compliance requires that the values be encrypted with a key the company controls and can rotate on demand, and that only a specific IAM role used by the application can decrypt them. Which configuration meets these requirements?
⚠ Common exam trap
The trap here is treating encryption key selection and IAM authorization as separate concerns, when a SecureString read actually requires both the Parameter Store API permission and a KMS decrypt permission.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create SecureString parameters using a customer managed KMS key, grant the application role ssm:GetParameter and kms:Decrypt on that key, and restrict the key policy to the application role.
Meeting the requirements needs two things at once: a customer managed KMS key so the company controls rotation and the key policy, and the right pair of permissions so the application can both read the parameter and decrypt it. SecureString is the only parameter type that encrypts values with KMS, and scoping the key policy to the application role enforces least privilege.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create SecureString parameters using a customer managed KMS key, grant the application role ssm:GetParameter and kms:Decrypt on that key, and restrict the key policy to the application role.
Why this is correct
A customer managed key gives the company full control over rotation and the key policy, which can limit decryption to the application role. SecureString parameters are encrypted with the specified KMS key, and the caller needs both ssm:GetParameter to read the parameter and kms:Decrypt to unwrap the data key, matching every stated requirement.
- ✗
Create SecureString parameters using the default aws/ssm key, and grant the application role ssm:GetParameter.
Why it's wrong here
The default aws/ssm key is an AWS-managed key, so the company cannot control its key policy or rotate it on demand. Granting only ssm:GetParameter also omits the kms:Decrypt permission needed to read a SecureString, so the application would fail to retrieve the plaintext value, violating both the control and access requirements.
- ✗
Create SecureString parameters using a customer managed KMS key, and grant the application role only kms:Decrypt on that key.
Why it's wrong here
Decryption permission alone is insufficient because the application also needs ssm:GetParameter to read the parameter resource from Parameter Store. Without that API permission the request is denied before KMS is ever involved, so the application cannot retrieve the configuration even though the key policy and encryption choice are correct.
- ✗
Create String parameters using a customer managed KMS key, and grant the application role ssm:GetParameter and kms:Decrypt on that key.
Why it's wrong here
The String parameter type stores plaintext and does not use a KMS key at all, so specifying a key has no effect and the values remain unencrypted. Although the IAM permissions are appropriate for SecureString retrieval, the parameter type chosen here fails the compliance requirement that values be encrypted under a company-controlled key.
Go deeper
Related to this question
About these practice questions
One of 935 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.