Amazon
SAA-C03 · Question #476
A solutions architect is storing sensitive data generated by an application in Amazon S3. The solutions architect wants to encrypt the data at rest. A company policy requires an audit trail of when th
Sign in or unlock SAA-C03 to reveal the answer and full explanation for question #476. The question stem and answer options stay visible for context.
Submitted by ngozi_ng· Mar 4, 2026Design Secure Architectures
Question
A solutions architect is storing sensitive data generated by an application in Amazon S3. The solutions architect wants to encrypt the data at rest. A company policy requires an audit trail of when the AWS KMS key was used and by whom. Which encryption option will meet these requirements?
Options
- AServer-side encryption with Amazon S3 managed keys (SSE-S3)
- BServer-side encryption with AWS KMS managed keys (SSE-KMS)
- CServer-side encryption with customer-provided keys (SSE-C)
- DServer-side encryption with self-managed keys
Unlock SAA-C03 to see the answer
You've previewed enough free SAA-C03 questions. Unlock SAA-C03 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.