SAA-C03 Design Secure Architectures Practice Question
Exhibit
Application log excerpt: 2026-04-11T09:14:22Z ERROR S3 GetObject failed: AccessDenied 2026-04-11T09:14:22Z ERROR KMS Decrypt failed for key arn:aws:kms:us-east-1:111122223333:key/abcd-1234 Current setup: - S3 bucket default encryption: SSE-KMS - EC2 application role: AppServerRole - Bucket policy allows s3:GetObject for AppServerRole - KMS key policy currently allows only the account root principal - No direct KMS permissions are attached to AppServerRole
Based on the exhibit, what is the most appropriate change to restore application access while keeping encryption at rest with customer-managed KMS controls?
⚠ Common exam trap
Many candidates assume S3 bucket policies alone control access to encrypted objects, forgetting that SSE-KMS requires separate KMS key permissions that must be explicitly granted to the IAM role or user.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Update the KMS key policy or add a grant so AppServerRole can use the key for decrypt and data key operations.
The application is failing because AppServerRole lacks the necessary permissions to use the customer-managed KMS key for decrypting S3 objects. By updating the KMS key policy or adding a grant to allow the role to perform `kms:Decrypt` and `kms:GenerateDataKey` operations, you restore access while maintaining encryption at rest with customer-managed KMS controls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Change the bucket to SSE-S3 so the application no longer depends on KMS permissions.
Why it's wrong here
SSE-S3 uses Amazon S3-managed keys (AES-256) where S3 handles encryption and decryption automatically with no separate KMS permission check. While this would eliminate the KMS dependency, it forfeits the customer-managed key control that SSE-KMS provides. The requirement specifically states the bucket should retain customer-managed encryption; changing to SSE-S3 would violate that requirement and is not a valid remediation for missing KMS permissions.
When this WOULD be correct
If the question required removing dependency on KMS permissions and allowed using AWS-managed keys, switching to SSE-S3 would simplify access without encryption errors.
- ✓
Update the KMS key policy or add a grant so AppServerRole can use the key for decrypt and data key operations.
Why this is correct
For SSE-KMS objects, the caller needs permission to use the KMS key as well as S3 permissions. The role already has S3 access, but KMS is denying Decrypt because the key policy does not allow the role. Adding the role through the key policy or a grant, together with the needed KMS actions, resolves the failure while preserving customer-managed encryption.
- ✗
Move the EC2 instance into the same Availability Zone as the S3 bucket to reduce encryption errors.
Why it's wrong here
Availability Zone (AZ) is a networking construct within an AWS Region; S3 is a regional service whose endpoints are not AZ-specific, and KMS is also a regional service (with multi-Region keys possible but not relevant here). The failure occurs because the role lacks KMS permissions, not because of network proximity. Moving the EC2 instance to another AZ would not alter IAM/KMS authorization or the key policy.
When this WOULD be correct
This option would be correct in a scenario where the application is experiencing high latency or data transfer costs due to cross-AZ data retrieval from S3, and the question asks for a change to reduce latency or cost while maintaining encryption at rest.
- ✗
Attach AmazonS3FullAccess to the application role so S3 can bypass KMS authorization.
Why it's wrong here
Attaching AmazonS3FullAccess gives broad S3 data-plane permissions, but for objects encrypted with SSE-KMS, S3 calls KMS to decrypt the object key before returning data. KMS authorization is a separate step: the IAM principal must have kms:Decrypt and kms:GenerateDataKey permissions (or be authorized by the key policy/grant). A full-access S3 policy does not confer any KMS permissions, and S3 cannot 'bypass' KMS enforcement. The decrypt call will still fail with AccessDenied unless the key policy allows the role.
When this WOULD be correct
This option would be correct if the question stated that the application needs full S3 access and encryption is not a concern (e.g., using SSE-S3 or no encryption), and the issue is a missing S3 permission rather than a KMS permission.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SAA-C03 exam frequently reuses these exact scenarios with slightly different constraints.
✓Update the KMS key policy or add a grant so AppServerRole can use the key for decrypt and data key operations.Correct answer▾
Why this is correct
For SSE-KMS objects, the caller needs permission to use the KMS key as well as S3 permissions. The role already has S3 access, but KMS is denying Decrypt because the key policy does not allow the role. Adding the role through the key policy or a grant, together with the needed KMS actions, resolves the failure while preserving customer-managed encryption.
✗Change the bucket to SSE-S3 so the application no longer depends on KMS permissions.Wrong answer — click to see why▾
Why this is wrong here
Changing to SSE-S3 removes customer-managed KMS controls, violating the requirement to keep encryption at rest with customer-managed KMS.
★ When this WOULD be the correct answer
If the question required removing dependency on KMS permissions and allowed using AWS-managed keys, switching to SSE-S3 would simplify access without encryption errors.
Why candidates choose this
Candidates may think SSE-S3 eliminates KMS permission issues, overlooking the explicit requirement for customer-managed KMS controls.
✗Move the EC2 instance into the same Availability Zone as the S3 bucket to reduce encryption errors.Wrong answer — click to see why▾
Why this is wrong here
Moving the EC2 instance into the same Availability Zone as the S3 bucket does not resolve encryption errors related to KMS permissions, as S3 is a regional service and Availability Zone placement does not affect KMS authorization.
★ When this WOULD be the correct answer
This option would be correct in a scenario where the application is experiencing high latency or data transfer costs due to cross-AZ data retrieval from S3, and the question asks for a change to reduce latency or cost while maintaining encryption at rest.
Why candidates choose this
Candidates may mistakenly believe that S3 operations are affected by network proximity at the AZ level, or confuse S3 with services like EC2 or EBS where AZ placement impacts performance and errors.
✗Attach AmazonS3FullAccess to the application role so S3 can bypass KMS authorization.Wrong answer — click to see why▾
Why this is wrong here
Attaching AmazonS3FullAccess does not bypass KMS authorization; S3 still requires KMS permissions to decrypt objects encrypted with customer-managed KMS keys, so the application would still fail.
★ When this WOULD be the correct answer
This option would be correct if the question stated that the application needs full S3 access and encryption is not a concern (e.g., using SSE-S3 or no encryption), and the issue is a missing S3 permission rather than a KMS permission.
Why candidates choose this
Candidates may think that granting full S3 access overrides all other permissions, not realizing that KMS has its own authorization layer that must be satisfied separately.
Analysis generated from the official SAA-C03blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SAA-C03 question from scratch — 935 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.