SAP-C02 Design for New Solutions Practice Question
A financial services company is building a new payment processing system on AWS. The system must durably retain transactional records for seven years to meet regulatory requirements, and the records must be encrypted at rest with a customer-provided key that the company can rotate on demand. The company wants the simplest operational model and does not want to manage any servers. Which solution should a solutions architect recommend?
⚠ Common exam trap
The trap here is assuming that any encrypted, highly durable storage service automatically supports customer-controlled key rotation and multi-year immutable retention.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Store records in Amazon S3 with a bucket policy that enforces SSE-KMS using a customer managed key, and use S3 Object Lock in compliance mode for the retention period.
The requirement for a customer-provided key that can be rotated on demand points to SSE-KMS with a customer managed key, and the seven-year immutable retention requirement points to S3 Object Lock in compliance mode. S3 offers the highest durability with no server management, making it the simplest solution that fully meets the regulatory, encryption, and operational requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Store records in Amazon S3 with a bucket policy that enforces SSE-KMS using a customer managed key, and use S3 Object Lock in compliance mode for the retention period.
Why this is correct
S3 provides eleven nines of durability, and SSE-KMS with a customer managed key lets the company rotate the key on demand through AWS KMS. S3 Object Lock in compliance mode enforces the seven-year retention immutably, and there are no servers to manage. This directly satisfies every stated requirement with minimal operational overhead.
- ✗
Store records in Amazon DynamoDB with encryption at rest using an AWS owned key, and enable point-in-time recovery with a seven-year retention window.
Why it's wrong here
Point-in-time recovery for DynamoDB retains data for a maximum of 35 days, not seven years, so it cannot meet the regulatory retention requirement. Additionally, an AWS owned key cannot be rotated by the company on demand. DynamoDB is a valid store for transactional data, but this specific configuration fails both the retention and key control requirements.
- ✗
Store records in Amazon S3 Glacier Deep Archive with server-side encryption using Amazon S3 managed keys (SSE-S3), and rely on S3 Versioning to prevent deletion for seven years.
Why it's wrong here
SSE-S3 uses keys fully managed by AWS, so the company cannot rotate a customer-provided key on demand. S3 Versioning alone does not prevent deletion; a user with permissions can still delete object versions. Glacier Deep Archive is durable, but this combination fails the customer-managed key rotation and immutability requirements.
- ✗
Store records in Amazon EBS volumes attached to EC2 instances, and use AWS KMS customer managed keys to encrypt the volumes. Configure a lifecycle policy to snapshot the volumes every day for seven years.
Why it's wrong here
EBS volumes are Availability Zone-scoped and require managing EC2 instances, which contradicts the no-server requirement. Daily snapshots do not guarantee seven-year retention of every individual record, and snapshot lifecycle policies cap retention. This approach adds operational burden and does not provide immutable, durable long-term retention of transactional records.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SAP-C02 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.