Courseiva
Design for New Solutions →mediumMultiple Choice

SAP-C02 Design for New Solutions Practice Question

A financial services company is building a new payment processing system on AWS. The system must durably retain transactional records for seven years to meet regulatory requirements, and the records must be encrypted at rest with a customer-provided key that the company can rotate on demand. The company wants the simplest operational model and does not want to manage any servers. Which solution should a solutions architect recommend?

⚠ Common exam trap

The trap here is assuming that any encrypted, highly durable storage service automatically supports customer-controlled key rotation and multi-year immutable retention.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Store records in Amazon S3 with a bucket policy that enforces SSE-KMS using a customer managed key, and use S3 Object Lock in compliance mode for the retention period.

The requirement for a customer-provided key that can be rotated on demand points to SSE-KMS with a customer managed key, and the seven-year immutable retention requirement points to S3 Object Lock in compliance mode. S3 offers the highest durability with no server management, making it the simplest solution that fully meets the regulatory, encryption, and operational requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Store records in Amazon S3 with a bucket policy that enforces SSE-KMS using a customer managed key, and use S3 Object Lock in compliance mode for the retention period.

    Why this is correct

    S3 provides eleven nines of durability, and SSE-KMS with a customer managed key lets the company rotate the key on demand through AWS KMS. S3 Object Lock in compliance mode enforces the seven-year retention immutably, and there are no servers to manage. This directly satisfies every stated requirement with minimal operational overhead.

  • ✗

    Store records in Amazon DynamoDB with encryption at rest using an AWS owned key, and enable point-in-time recovery with a seven-year retention window.

    Why it's wrong here

    Point-in-time recovery for DynamoDB retains data for a maximum of 35 days, not seven years, so it cannot meet the regulatory retention requirement. Additionally, an AWS owned key cannot be rotated by the company on demand. DynamoDB is a valid store for transactional data, but this specific configuration fails both the retention and key control requirements.

  • ✗

    Store records in Amazon S3 Glacier Deep Archive with server-side encryption using Amazon S3 managed keys (SSE-S3), and rely on S3 Versioning to prevent deletion for seven years.

    Why it's wrong here

    SSE-S3 uses keys fully managed by AWS, so the company cannot rotate a customer-provided key on demand. S3 Versioning alone does not prevent deletion; a user with permissions can still delete object versions. Glacier Deep Archive is durable, but this combination fails the customer-managed key rotation and immutability requirements.

  • ✗

    Store records in Amazon EBS volumes attached to EC2 instances, and use AWS KMS customer managed keys to encrypt the volumes. Configure a lifecycle policy to snapshot the volumes every day for seven years.

    Why it's wrong here

    EBS volumes are Availability Zone-scoped and require managing EC2 instances, which contradicts the no-server requirement. Daily snapshots do not guarantee seven-year retention of every individual record, and snapshot lifecycle policies cap retention. This approach adds operational burden and does not provide immutable, durable long-term retention of transactional records.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SAP-C02 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.