For IndividualsFor Educators
ExpertMinds LogoExpertMinds
ExpertMinds

Ace your certifications with Practice Exams and AI assistance.

  • Browse Exams
  • For Educators
  • Blog
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Support
  • AWS SAA Exam Prep
  • PMI PMP Exam Prep
  • CPA Exam Prep
  • GCP PCA Exam Prep

© 2026 TinyHive Labs. Company number 16262776.

    PracticeAWS Solutions Architect Associate (SAA-C03)AWS SAA-C03 Practice Exam 4Question 06
    Easy1 markMultiple Choice
    Domain 1.3: Data SecuritySecurityS3KMSEncryption

    AWS SAA-C03 · Question 06 · Domain 1.3: Data Security

    A company requires that all data stored in Amazon S3 must be encrypted at rest using keys managed by the company. The company wants to maintain full control over the key rotation and auditing of key usage. <br/><br/>Which encryption option meets these requirements?

    Answer options:

    A.

    Server-Side Encryption with Amazon S3 Managed Keys (SSE-S3)

    B.

    Server-Side Encryption with AWS KMS AWS Managed Keys (SSE-KMS)

    C.

    Server-Side Encryption with AWS KMS Customer Managed Keys (SSE-KMS)

    D.

    Client-Side Encryption using the AWS Encryption SDK

    How to approach this question

    Identify the KMS key type that provides the customer with full control over rotation and policies.

    Full Answer

    C.Server-Side Encryption with AWS KMS Customer Managed Keys (SSE-KMS)✓ Correct
    AWS KMS Customer Managed Keys provide the highest level of control. You can establish and maintain their key policies, IAM policies, and grants, enable and disable them, rotate their cryptographic material, and audit their usage in AWS CloudTrail.

    Common mistakes

    Confusing AWS Managed Keys with Customer Managed Keys.
    Question 05All questionsQuestion 07

    Practice the full AWS SAA-C03 Practice Exam 4

    65 questions · hints · full answers · grading

    Sign up freeTake the exam

    More questions from this exam

    Q01A company has multiple AWS accounts in an AWS Organizations organization. The security team wants...MediumQ02An application running on Amazon EC2 instances needs to access an Amazon DynamoDB table. Both res...EasyQ03A company is designing a web application that will be hosted on AWS. The application will use an ...MediumQ04A company is building a mobile app that requires users to authenticate using their social media a...HardQ05A solutions architect is designing a VPC for a three-tier web application. The database tier must...Medium
    View all 65 questions →