Courseiva
Design Secure Architectures →mediumMultiple Choice

SAA-C03 Design Secure Architectures Practice Question

Exhibit

Application log excerpt:

2026-04-11T09:14:22Z ERROR S3 GetObject failed: AccessDenied
2026-04-11T09:14:22Z ERROR KMS Decrypt failed for key arn:aws:kms:us-east-1:111122223333:key/abcd-1234

Current setup:
- S3 bucket default encryption: SSE-KMS
- EC2 application role: AppServerRole
- Bucket policy allows s3:GetObject for AppServerRole
- KMS key policy currently allows only the account root principal
- No direct KMS permissions are attached to AppServerRole

Based on the exhibit, what is the most appropriate change to restore application access while keeping encryption at rest with customer-managed KMS controls?

⚠ Common exam trap

Many candidates assume S3 bucket policies alone control access to encrypted objects, forgetting that SSE-KMS requires separate KMS key permissions that must be explicitly granted to the IAM role or user.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Update the KMS key policy or add a grant so AppServerRole can use the key for decrypt and data key operations.

The application is failing because AppServerRole lacks the necessary permissions to use the customer-managed KMS key for decrypting S3 objects. By updating the KMS key policy or adding a grant to allow the role to perform `kms:Decrypt` and `kms:GenerateDataKey` operations, you restore access while maintaining encryption at rest with customer-managed KMS controls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Change the bucket to SSE-S3 so the application no longer depends on KMS permissions.

    Why it's wrong here

    SSE-S3 uses Amazon S3-managed keys (AES-256) where S3 handles encryption and decryption automatically with no separate KMS permission check. While this would eliminate the KMS dependency, it forfeits the customer-managed key control that SSE-KMS provides. The requirement specifically states the bucket should retain customer-managed encryption; changing to SSE-S3 would violate that requirement and is not a valid remediation for missing KMS permissions.

    When this WOULD be correct

    If the question required removing dependency on KMS permissions and allowed using AWS-managed keys, switching to SSE-S3 would simplify access without encryption errors.

  • ✓

    Update the KMS key policy or add a grant so AppServerRole can use the key for decrypt and data key operations.

    Why this is correct

    For SSE-KMS objects, the caller needs permission to use the KMS key as well as S3 permissions. The role already has S3 access, but KMS is denying Decrypt because the key policy does not allow the role. Adding the role through the key policy or a grant, together with the needed KMS actions, resolves the failure while preserving customer-managed encryption.

  • ✗

    Move the EC2 instance into the same Availability Zone as the S3 bucket to reduce encryption errors.

    Why it's wrong here

    Availability Zone (AZ) is a networking construct within an AWS Region; S3 is a regional service whose endpoints are not AZ-specific, and KMS is also a regional service (with multi-Region keys possible but not relevant here). The failure occurs because the role lacks KMS permissions, not because of network proximity. Moving the EC2 instance to another AZ would not alter IAM/KMS authorization or the key policy.

    When this WOULD be correct

    This option would be correct in a scenario where the application is experiencing high latency or data transfer costs due to cross-AZ data retrieval from S3, and the question asks for a change to reduce latency or cost while maintaining encryption at rest.

  • ✗

    Attach AmazonS3FullAccess to the application role so S3 can bypass KMS authorization.

    Why it's wrong here

    Attaching AmazonS3FullAccess gives broad S3 data-plane permissions, but for objects encrypted with SSE-KMS, S3 calls KMS to decrypt the object key before returning data. KMS authorization is a separate step: the IAM principal must have kms:Decrypt and kms:GenerateDataKey permissions (or be authorized by the key policy/grant). A full-access S3 policy does not confer any KMS permissions, and S3 cannot 'bypass' KMS enforcement. The decrypt call will still fail with AccessDenied unless the key policy allows the role.

    When this WOULD be correct

    This option would be correct if the question stated that the application needs full S3 access and encryption is not a concern (e.g., using SSE-S3 or no encryption), and the issue is a missing S3 permission rather than a KMS permission.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SAA-C03 exam frequently reuses these exact scenarios with slightly different constraints.

✓Update the KMS key policy or add a grant so AppServerRole can use the key for decrypt and data key operations.Correct answer▾

Why this is correct

For SSE-KMS objects, the caller needs permission to use the KMS key as well as S3 permissions. The role already has S3 access, but KMS is denying Decrypt because the key policy does not allow the role. Adding the role through the key policy or a grant, together with the needed KMS actions, resolves the failure while preserving customer-managed encryption.

✗Change the bucket to SSE-S3 so the application no longer depends on KMS permissions.Wrong answer — click to see why▾

Why this is wrong here

Changing to SSE-S3 removes customer-managed KMS controls, violating the requirement to keep encryption at rest with customer-managed KMS.

★ When this WOULD be the correct answer

If the question required removing dependency on KMS permissions and allowed using AWS-managed keys, switching to SSE-S3 would simplify access without encryption errors.

Why candidates choose this

Candidates may think SSE-S3 eliminates KMS permission issues, overlooking the explicit requirement for customer-managed KMS controls.

✗Move the EC2 instance into the same Availability Zone as the S3 bucket to reduce encryption errors.Wrong answer — click to see why▾

Why this is wrong here

Moving the EC2 instance into the same Availability Zone as the S3 bucket does not resolve encryption errors related to KMS permissions, as S3 is a regional service and Availability Zone placement does not affect KMS authorization.

★ When this WOULD be the correct answer

This option would be correct in a scenario where the application is experiencing high latency or data transfer costs due to cross-AZ data retrieval from S3, and the question asks for a change to reduce latency or cost while maintaining encryption at rest.

Why candidates choose this

Candidates may mistakenly believe that S3 operations are affected by network proximity at the AZ level, or confuse S3 with services like EC2 or EBS where AZ placement impacts performance and errors.

✗Attach AmazonS3FullAccess to the application role so S3 can bypass KMS authorization.Wrong answer — click to see why▾

Why this is wrong here

Attaching AmazonS3FullAccess does not bypass KMS authorization; S3 still requires KMS permissions to decrypt objects encrypted with customer-managed KMS keys, so the application would still fail.

★ When this WOULD be the correct answer

This option would be correct if the question stated that the application needs full S3 access and encryption is not a concern (e.g., using SSE-S3 or no encryption), and the issue is a missing S3 permission rather than a KMS permission.

Why candidates choose this

Candidates may think that granting full S3 access overrides all other permissions, not realizing that KMS has its own authorization layer that must be satisfied separately.

Analysis generated from the official SAA-C03blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SAA-C03 question from scratch — 935 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.