Courseiva

SAA-C03 Design Secure Architectures Practice Question

A company has an Amazon S3 bucket for sensitive reports. They must ensure that any object uploaded with s3:PutObject is encrypted using AWS KMS (SSE-KMS). Which S3 bucket policy approach best enforces this by denying uploads that do not use SSE-KMS?

⚠ Common exam trap

Watch out — candidates often confuse encryption in transit (HTTPS) with encryption at rest (SSE), leading them to pick Option B, which only ensures secure transport but does not enforce server-side encryption with KMS.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a Deny statement for s3:PutObject with a condition that denies requests where s3:x-amz-server-side-encryption is not "aws:kms" (SSE-KMS), for example: Condition { StringNotEquals: { "s3:x-amz-server-side-encryption": "aws:kms" } }

It uses a Deny statement with the condition `StringNotEquals` on the `s3:x-amz-server-side-encryption` request header, which explicitly denies any `s3:PutObject` request that does not include the value `aws:kms` for that header. This ensures that only objects encrypted with SSE-KMS are uploaded, as any request lacking the header or using a different encryption type (e.g., AES256) will be denied. The condition is evaluated at the time of the request, making it an effective enforcement mechanism.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use a Deny statement for s3:PutObject with a condition that denies requests where s3:x-amz-server-side-encryption is not "aws:kms" (SSE-KMS), for example: Condition { StringNotEquals: { "s3:x-amz-server-side-encryption": "aws:kms" } }

    Why this is correct

    This directly checks the SSE encryption header used in the PutObject request. If a client uploads without SSE-KMS (for example, no encryption header or SSE-S3/AES256), the condition evaluates to true and the Deny prevents the upload.

  • ✗

    Use a Deny statement that denies requests when aws:SecureTransport is false.

    Why it's wrong here

    The aws:SecureTransport condition key only verifies that the request was sent over HTTPS (TLS); it never inspects the object's encryption headers. A client could upload a sensitive object using SSE-S3 (AES256) or no encryption at all while still using a secure transport layer, leaving the object unencrypted with SSE-KMS at rest. Therefore, denying requests where SecureTransport is false fails to fulfill the requirement because it neither checks the s3:x-amz-server-side-encryption header nor enforces encryption at rest.

  • ✗

    Use a Deny statement that checks the specific KMS key ID (s3:x-amz-server-side-encryption-aws-kms-key-id) and denies requests that don’t match a single alias value.

    Why it's wrong here

    This enforces use of one particular KMS key/alias, which is more restrictive than the requirement (the requirement is only to use SSE-KMS, not a specific key). The best answer should enforce SSE-KMS generally, not a specific key identity.

  • ✗

    Use a Deny or Allow statement that limits object keys using s3:prefix (for example, only allow keys under "reports/").

    Why it's wrong here

    A condition on s3:prefix, such as only allowing keys under 'reports/', constrains the object naming path but has no effect on the request headers that choose server-side encryption. An object written to reports/ could be uploaded with SSE-S3, SSE-KMS, or even without encryption if the bucket's default encryption is not enforced, meaning the denial would not guarantee KMS protection. Additionally, prefix-based conditions are resource-level access controls, not encryption-specific condition keys, so they are the wrong mechanism for this requirement.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.