Skip to content
BytePatterns

SAA-C03 · Domain 1: Design Secure Architectures · 30% of the exam

Task 1.3: Determine appropriate data security controls.

Protecting the data itself: encryption at rest with KMS and in transit with TLS certificates, who may use a key, rotation, backups and replication, and lifecycle and retention rules that satisfy an auditor.

Study it

  • Resource-based policies and S3 access: bucket policies, Block Public Access, presigned URLs

    Lesson coming

  • Encryption and keys: KMS key policies, envelope encryption, rotation, ACM and TLS

    Partly covered by: KMS, Envelope Encryption & Private CA

  • Data protection: backups, replication, retention and Object Lock

    Lesson coming

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 1

A company stores regulated documents in Amazon S3. Auditors require that the company controls who can use the encryption key through its own key policy, can see every use of the key in AWS CloudTrail, and can disable the key at any time. Which encryption option meets all of these requirements?

  1. AServer-side encryption with Amazon S3 managed keys (SSE-S3)
  2. BServer-side encryption with the AWS managed key aws/s3 (SSE-KMS)
  3. CServer-side encryption with customer-provided keys (SSE-C)
  4. DServer-side encryption with a customer managed KMS key (SSE-KMS)
Show the answer and why
  • AServer-side encryption with Amazon S3 managed keys (SSE-S3)

    Incorrect

    With SSE-S3, Amazon S3 manages the keys. There is no key policy for the company to write and no key to disable.

  • BServer-side encryption with the AWS managed key aws/s3 (SSE-KMS)

    Incorrect

    Use of an AWS managed key appears in CloudTrail, but you cannot change its key policy or any of its properties, so you cannot disable it.

  • CServer-side encryption with customer-provided keys (SSE-C)

    Incorrect

    With SSE-C the company manages its keys outside AWS and sends them with each request. There is no KMS key policy, and the key's use is not tracked in AWS KMS.

  • DServer-side encryption with a customer managed KMS key (SSE-KMS)

    Correct

    A customer managed key is created and controlled by the company: it writes the key policy, can enable or disable the key, and every use is logged in CloudTrail.

Own key policy, audit trail and the power to disable: only a customer managed KMS key gives all three. AWS managed keys are auditable but not controllable.

Question 2 · choose 1

A healthcare company has hundreds of S3 buckets created by different teams over several years. Compliance officers need an automated, ongoing way to find out which buckets hold personal data such as names, addresses and patient record numbers. Which AWS service should they use?

  1. AAmazon GuardDuty with S3 protection turned on
  2. BAmazon Macie with automated data discovery
  3. CAmazon Inspector with continuous scanning on
  4. DAWS Config with managed rules for S3 buckets
Show the answer and why
  • AAmazon GuardDuty with S3 protection turned on

    Incorrect

    GuardDuty is a threat detection service that analyzes activity in logs. It does not classify what the stored objects contain.

  • BAmazon Macie with automated data discovery

    Correct

    Macie discovers sensitive data in S3 with machine learning and pattern matching, and automates discovery and reporting across buckets.

  • CAmazon Inspector with continuous scanning on

    Incorrect

    Inspector scans EC2 instances, container images and Lambda functions for software vulnerabilities and network exposure, not S3 data.

  • DAWS Config with managed rules for S3 buckets

    Incorrect

    Config evaluates how resources are configured, for example whether a bucket is public. It does not look inside objects for personal data.

Finding sensitive data inside S3 objects is Macie's job. GuardDuty watches activity, Inspector watches software, and Config watches configuration.

Question 3 · choose 1

A company serves a public website through an Application Load Balancer. Its certificate is bought from a third-party authority, imported, and replaced by hand, and it expired once last year. The company wants TLS certificates that renew automatically with no manual steps. What should a solutions architect do?

  1. AKeep importing the third-party certificate into ACM, and let ACM renew it automatically before it expires
  2. BUpload the third-party certificate to IAM as a server certificate and attach it to the HTTPS listener
  3. CRequest a public ACM certificate with DNS validation and use it on the load balancer's HTTPS listener
  4. DKeep the certificate's private key in an AWS CloudHSM cluster and point the HTTPS listener at the cluster
Show the answer and why
  • AKeep importing the third-party certificate into ACM, and let ACM renew it automatically before it expires

    Incorrect

    ACM does not provide managed renewal for imported certificates. You must get a new certificate from the issuer and import it again.

  • BUpload the third-party certificate to IAM as a server certificate and attach it to the HTTPS listener

    Incorrect

    IAM can store server certificates, but you upload and replace them yourself. AWS names ACM as the preferred tool, and only ACM certificates renew automatically.

  • CRequest a public ACM certificate with DNS validation and use it on the load balancer's HTTPS listener

    Correct

    ACM provides managed renewal for the certificates it issues; with DNS validation and the certificate in use by the load balancer, renewal is automatic.

  • DKeep the certificate's private key in an AWS CloudHSM cluster and point the HTTPS listener at the cluster

    Incorrect

    CloudHSM provides hardware security modules for keys you manage. It does not issue or renew certificates.

Automatic renewal belongs to certificates that ACM issues. Imported certificates and IAM server certificates stay a manual job.

Question 4 · choose 1

A financial company must keep backups of its Amazon RDS databases and Amazon EBS volumes for 7 years. Regulators require that nobody, including the root user, can delete the backups or shorten their retention during that time. Which solution meets these requirements?

  1. AUse AWS Backup with a plan that keeps recovery points for 7 years in a backup vault locked in compliance mode
  2. BTurn on RDS automated backups with the longest retention period, and take daily EBS snapshots with a lifecycle policy
  3. CUse AWS Backup with a plan that keeps recovery points for 7 years in a backup vault locked in governance mode
  4. DExport the backups to an S3 bucket with S3 Versioning on and a lifecycle rule that expires the objects after 7 years
Show the answer and why
  • AUse AWS Backup with a plan that keeps recovery points for 7 years in a backup vault locked in compliance mode

    Correct

    Once the grace time ends, a compliance-mode vault lock cannot be changed or deleted by anyone, including the root user, while it holds recovery points.

  • BTurn on RDS automated backups with the longest retention period, and take daily EBS snapshots with a lifecycle policy

    Incorrect

    RDS automated backups can be kept for at most 35 days, and nothing stops a privileged user from deleting snapshots.

  • CUse AWS Backup with a plan that keeps recovery points for 7 years in a backup vault locked in governance mode

    Incorrect

    A vault locked in governance mode can have its lock removed by users with sufficient IAM permissions, so it does not stop everyone.

  • DExport the backups to an S3 bucket with S3 Versioning on and a lifecycle rule that expires the objects after 7 years

    Incorrect

    Versioning keeps earlier versions, but a user with permission can still delete them. Write-once protection in S3 needs Object Lock.

"Nobody, including root" is the wording of compliance mode. Governance mode can be lifted by privileged users, and plain retention settings can be shortened.

Question 5 · choose 2

Account A stores objects in an S3 bucket encrypted with SSE-KMS and a customer managed key in account A. The bucket policy already allows a role in account B to read the objects, but the role gets AccessDenied errors from AWS KMS. Which changes are required so that the role can read the objects? (Choose TWO.)

  1. ATurn on automatic key rotation for the customer managed key in account A
  2. BAdd a key policy statement in account A that lets account B use the key to decrypt
  3. CRe-encrypt the objects with the AWS managed key aws/s3 so that account B can use it
  4. DAttach an IAM policy to the role in account B that allows kms:Decrypt on the key's ARN
  5. EAttach an SCP to account B that allows kms:Decrypt on every key that account A owns
Show the answer and why
  • ATurn on automatic key rotation for the customer managed key in account A

    Incorrect

    Rotation replaces the key material. It does not change who is allowed to use the key.

  • BAdd a key policy statement in account A that lets account B use the key to decrypt

    Correct

    Cross-account use of a KMS key needs the key policy in the owning account to allow the external account.

  • CRe-encrypt the objects with the AWS managed key aws/s3 so that account B can use it

    Incorrect

    You cannot change the key policy of an AWS managed key, so you cannot grant another account access to it.

  • DAttach an IAM policy to the role in account B that allows kms:Decrypt on the key's ARN

    Correct

    The external account must also delegate the permission to its own role through an IAM policy.

  • EAttach an SCP to account B that allows kms:Decrypt on every key that account A owns

    Incorrect

    An SCP never grants permissions; it only limits what identity policies in the account can allow.

Cross-account KMS access takes two policies: the key policy in the key's account and an IAM policy in the caller's account. AWS managed keys cannot be shared this way.

Question 6 · choose 1

Audit log files written to an S3 bucket must be write-once-read-many for 5 years: during that time no user, including the root user, may overwrite or delete any version. Which configuration meets this requirement?

  1. AS3 Object Lock in compliance mode with a 5-year default retention period
  2. BS3 Versioning with a bucket policy that denies s3:DeleteObject to everyone
  3. CS3 Object Lock in governance mode with a 5-year default retention period
  4. DS3 Versioning with an S3 Lifecycle rule that keeps noncurrent versions 5 years
Show the answer and why
  • AS3 Object Lock in compliance mode with a 5-year default retention period

    Correct

    In compliance mode, no user, including the root user, can overwrite or delete a protected object version until its retention period ends.

  • BS3 Versioning with a bucket policy that denies s3:DeleteObject to everyone

    Incorrect

    A privileged user can change or remove the bucket policy and then delete versions.

  • CS3 Object Lock in governance mode with a 5-year default retention period

    Incorrect

    In governance mode, users with special permissions can override or remove the retention settings.

  • DS3 Versioning with an S3 Lifecycle rule that keeps noncurrent versions 5 years

    Incorrect

    Lifecycle rules control when versions expire; they do not stop a user from deleting them earlier.

WORM that nobody can bypass is Object Lock compliance mode; governance mode can be overridden by privileged users.

Question 7 · choose 1

An unencrypted Amazon RDS for MySQL DB instance must be encrypted at rest with a KMS key to meet a new policy. What should a solutions architect do?

  1. AModify the DB instance and turn on encryption at rest in the next maintenance window
  2. BCreate an encrypted read replica of the instance and then promote that replica
  3. CRestore the latest automated backup of the instance into a new encrypted instance
  4. DSnapshot the instance, make an encrypted copy, and restore a new instance from it
Show the answer and why
  • AModify the DB instance and turn on encryption at rest in the next maintenance window

    Incorrect

    RDS can encrypt a DB instance only when it is created, not by modifying an existing one.

  • BCreate an encrypted read replica of the instance and then promote that replica

    Incorrect

    RDS does not allow an encrypted read replica of an unencrypted DB instance.

  • CRestore the latest automated backup of the instance into a new encrypted instance

    Incorrect

    An unencrypted backup or snapshot cannot be restored to an encrypted DB instance directly.

  • DSnapshot the instance, make an encrypted copy, and restore a new instance from it

    Correct

    Encryption can only be set when an instance is created, but an encrypted copy of a snapshot can be restored into an encrypted instance.

Snapshot, encrypted copy, restore: that is the documented path to encrypt an existing unencrypted RDS instance.

Question 8 · choose 1

An auditor finds that some clients read objects from an S3 bucket over plain HTTP. The company must reject every request to the bucket that does not use TLS. What should a solutions architect do?

  1. AAdd a bucket policy that denies requests when aws:SecureTransport is false
  2. BTurn on default encryption with SSE-KMS for every object in the bucket
  3. CTurn on S3 Block Public Access for the bucket and for the whole account
  4. DIssue an ACM certificate for the bucket and attach it to the bucket's S3 endpoint
Show the answer and why
  • AAdd a bucket policy that denies requests when aws:SecureTransport is false

    Correct

    AWS recommends allowing only HTTPS connections with the aws:SecureTransport condition in bucket policies.

  • BTurn on default encryption with SSE-KMS for every object in the bucket

    Incorrect

    SSE-KMS protects data at rest. It does not control whether requests use an encrypted connection.

  • CTurn on S3 Block Public Access for the bucket and for the whole account

    Incorrect

    Block Public Access stops public access grants; it does not reject unencrypted connections from allowed callers.

  • DIssue an ACM certificate for the bucket and attach it to the bucket's S3 endpoint

    Incorrect

    ACM certificates are deployed to integrated services such as load balancers and CloudFront, not attached to an S3 bucket endpoint.

Encryption in transit for S3 is enforced in the bucket policy with aws:SecureTransport.

Question 9 · choose 1

A company encrypts data with a symmetric customer managed KMS key whose key material AWS KMS generated. A new policy requires the key material to change at least once a year, while data encrypted earlier must stay readable without re-encryption. Which solution needs the LEAST effort?

  1. ACreate a new KMS key every year and re-encrypt all data under the new key
  2. BTurn on automatic key rotation for the existing customer managed key
  3. CSwitch the data to the AWS managed key and rotate that key manually each year
  4. DChange the key policy each year so that a new set of roles can use the key
Show the answer and why
  • ACreate a new KMS key every year and re-encrypt all data under the new key

    Incorrect

    It works, but re-encrypting all data every year is a large recurring job that rotation makes unnecessary.

  • BTurn on automatic key rotation for the existing customer managed key

    Correct

    Automatic rotation generates new key material on a schedule (yearly by default) and keeps the old material to decrypt existing data.

  • CSwitch the data to the AWS managed key and rotate that key manually each year

    Incorrect

    You cannot rotate or change the properties of AWS managed keys.

  • DChange the key policy each year so that a new set of roles can use the key

    Incorrect

    Changing who may use a key does not change its key material.

KMS rotation swaps the current key material but keeps the older material to decrypt what it encrypted, so nothing has to be re-encrypted.

Question 10 · choose 1

A bug in an application occasionally overwrites items in a DynamoDB table. The company must be able to restore the table to its state at any second within the last 30 days, with no backup jobs to schedule. What should a solutions architect do?

  1. ASchedule a daily on-demand backup and keep the backups for 30 days
  2. BTurn the table into a global table with a replica in a second Region
  3. CTurn on point-in-time recovery with a 30-day or longer recovery period
  4. DAdd a TTL attribute so that overwritten items are removed after 30 days
Show the answer and why
  • ASchedule a daily on-demand backup and keep the backups for 30 days

    Incorrect

    Daily backups can restore only to the moment each backup was taken, so up to a day of changes could be lost.

  • BTurn the table into a global table with a replica in a second Region

    Incorrect

    Replicas copy every write, including the bad ones, so they do not provide an earlier state to restore.

  • CTurn on point-in-time recovery with a 30-day or longer recovery period

    Correct

    PITR keeps continuous backups with per-second recovery points for up to 35 days, with nothing to schedule.

  • DAdd a TTL attribute so that overwritten items are removed after 30 days

    Incorrect

    TTL deletes expired items; it does not keep earlier versions of items to restore.

Per-second recovery without scheduled jobs is DynamoDB point-in-time recovery.

Practise domain 1 →Practise all domains →