SAA-C03 Design Secure Architectures Practice Question
Exhibit
CloudTrail event summary:
- eventSource: kms.amazonaws.com
- eventName: Decrypt
- errorCode: AccessDeniedException
- userIdentity: arn:aws:sts::444455556666:assumed-role/PartnerUploadRole/partner-app
- requestParameters.keyId: arn:aws:kms:us-east-1:111122223333:key/6b2f-9a7c
Current CMK key policy excerpt in account 111122223333:
{
"Sid": "EnableRootPermissionsOnly",
"Effect": "Allow",
"Principal": { "AWS": "arn:aws:iam::111122223333:root" },
"Action": "kms:*",
"Resource": "*"
}Based on the exhibit, a partner account uploads encrypted objects to a central S3 bucket and later reads them back. The S3 permissions are correct, but the requests still fail. What change is required so the partner workload can use the customer-managed KMS key safely?
⚠ Common exam trap
A common mix-up: candidates assume the S3 bucket policy alone is sufficient for cross-account access with SSE-KMS, forgetting that KMS requires its own separate authorization via the key policy or a grant, which is a frequent point of failure in multi-account architectures.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Update the CMK key policy, or add a tightly scoped grant, to allow the partner role the required KMS actions through S3.
When using a customer-managed KMS key (CMK) for SSE-KMS in a cross-account scenario, the key policy must explicitly grant the partner account's IAM role the necessary KMS actions (kms:Decrypt, kms:GenerateDataKey) to allow S3 to perform the encryption/decryption on behalf of the partner. Without this policy update or a tightly scoped grant, S3 cannot authorize the KMS operation even if the S3 bucket policy permits the upload/read.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Replace SSE-KMS with S3 object ACLs so the partner account can bypass KMS authorization.
Why it's wrong here
S3 object ACLs are legacy access list controls that govern who can read or write an object at the S3 API level; they do not influence AWS KMS authorization in any way. The AccessDenied error in this scenario is raised by KMS when S3 tries to decrypt the object's envelope key using the customer-managed CMK. Since ACLs cannot grant kms:Decrypt permissions on the CMK, changing them cannot bypass cryptographic authorization, and the partner account still lacks the required KMS access.
When this WOULD be correct
This would be correct if the question asked for a way to grant cross-account access to S3 objects without encryption, or if the objects were not encrypted and the issue was solely about S3 permissions.
- ✗
Create a new bucket in the partner account and copy the objects there to avoid cross-account encryption.
Why it's wrong here
Creating a new bucket in the partner account and copying the objects is an architectural workaround, not a resolution of the KMS trust misconfiguration. The copy operation would require decrypting each object with the CMK first, then re-encrypting under the partner account's own key, which adds significant bandwidth, cost, and potential data exposure during transfer. It also leaves the original bucket's KMS key policy broken and maintains duplicate data, needlessly complicating the architecture rather than granting the partner role the minimal KMS actions through a policy or grant.
When this WOULD be correct
This option would be correct if the question required isolating data to avoid cross-account access entirely, such as when regulatory compliance mandates that data must not leave the partner's account, or when the central bucket policy cannot be modified to grant cross-account permissions.
- ✗
Switch the bucket to SSE-S3 so the partner role no longer needs KMS permissions.
Why it's wrong here
Switching the bucket to SSE-S3 would indeed remove the partner's need for KMS permissions because S3 fully manages those encryption keys, but it abandons the customer-managed key entirely. The scenario calls for using a CMK, likely to meet security or compliance requirements; SSE-S3 lacks per-key policies, audit trails, and the ability to rotate or revoke the key independently. Existing objects encrypted under the CMK would have to be rewritten to the new encryption type, and this is a workaround that doesn't fix the underlying trust policy configuration.
When this WOULD be correct
This option would be correct if the question specified that the objects are encrypted with SSE-KMS (AWS managed key) and the partner workload does not need KMS permissions, or if the requirement is to simplify encryption and the objects are not sensitive. For example, a scenario where cost reduction or eliminating KMS key management is the goal.
- ✓
Update the CMK key policy, or add a tightly scoped grant, to allow the partner role the required KMS actions through S3.
Why this is correct
Cross-account access to SSE-KMS encrypted objects requires KMS authorization in addition to S3 authorization. The key policy must trust the partner role, and the permissions should be limited to the needed KMS actions such as Decrypt, Encrypt, and GenerateDataKey with a service condition for S3. That is why the partner can have valid S3 permissions and still fail until the KMS policy is fixed.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SAA-C03 exam frequently reuses these exact scenarios with slightly different constraints.
✓Update the CMK key policy, or add a tightly scoped grant, to allow the partner role the required KMS actions through S3.Correct answer▾
Why this is correct
Cross-account access to SSE-KMS encrypted objects requires KMS authorization in addition to S3 authorization. The key policy must trust the partner role, and the permissions should be limited to the needed KMS actions such as Decrypt, Encrypt, and GenerateDataKey with a service condition for S3. That is why the partner can have valid S3 permissions and still fail until the KMS policy is fixed.
✗Replace SSE-KMS with S3 object ACLs so the partner account can bypass KMS authorization.Wrong answer — click to see why▾
Why this is wrong here
S3 object ACLs do not bypass KMS authorization; the partner workload still needs KMS permissions to decrypt objects encrypted with a customer-managed KMS key. ACLs only control S3-level access, not encryption key access.
★ When this WOULD be the correct answer
This would be correct if the question asked for a way to grant cross-account access to S3 objects without encryption, or if the objects were not encrypted and the issue was solely about S3 permissions.
Why candidates choose this
Candidates may think ACLs provide a simpler alternative to KMS policies, misunderstanding that ACLs cannot override KMS encryption requirements.
✗Create a new bucket in the partner account and copy the objects there to avoid cross-account encryption.Wrong answer — click to see why▾
Why this is wrong here
Creating a new bucket in the partner account and copying objects there does not solve the cross-account KMS authorization issue; the partner still needs KMS permissions to decrypt objects encrypted with the customer-managed KMS key, and moving objects does not grant those permissions.
★ When this WOULD be the correct answer
This option would be correct if the question required isolating data to avoid cross-account access entirely, such as when regulatory compliance mandates that data must not leave the partner's account, or when the central bucket policy cannot be modified to grant cross-account permissions.
Why candidates choose this
Candidates may think that moving objects to the partner's own bucket eliminates the need for cross-account KMS permissions, overlooking that the objects are already encrypted with the customer's KMS key and decryption still requires access to that key.
✗Switch the bucket to SSE-S3 so the partner role no longer needs KMS permissions.Wrong answer — click to see why▾
Why this is wrong here
Switching to SSE-S3 would remove KMS encryption, but the question states the objects are encrypted with a customer-managed KMS key (CMK). Changing encryption type is not a valid fix for KMS authorization issues; the partner workload must use the same CMK to read back the objects.
★ When this WOULD be the correct answer
This option would be correct if the question specified that the objects are encrypted with SSE-KMS (AWS managed key) and the partner workload does not need KMS permissions, or if the requirement is to simplify encryption and the objects are not sensitive. For example, a scenario where cost reduction or eliminating KMS key management is the goal.
Why candidates choose this
Candidates may think switching to SSE-S3 is a quick way to bypass KMS permission issues without understanding that it changes the encryption method and may violate security requirements. They might also assume that S3 handles all encryption authorization automatically.
Analysis generated from the official SAA-C03blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.