S3 can encrypt your objects at rest, and the exam tests that you know the options and who controls the keys. Encryption in transit uses HTTPS; encryption at rest uses one of several server-side options.

The encryption options

SSE-S3 — S3 manages the keys for you (simplest). SSE-KMS — keys managed in AWS KMS, giving you rotation, policies, and CloudTrail auditing of key use. SSE-C — you supply and manage the keys yourself. Client-side encryption means you encrypt before upload. When the scenario needs audit trails and control over keys, that’s SSE-KMS.

Test yourself

Practice question

A company must encrypt S3 objects at rest and needs an audit trail of every time the encryption key is used, plus control over key rotation. Which option?

  1. SSE-S3
  2. SSE-KMS
  3. No encryption, use a bucket policy
  4. SSE-C
👉 Click to reveal the answer & explanation

Correct answer: B. SSE-KMS uses KMS-managed keys with rotation, key policies, and CloudTrail logging of key usage — the audit trail requirement. SSE-S3 (A) gives no key-level control or audit; a bucket policy (C) isn’t encryption; SSE-C (D) offloads key management to you without KMS auditing.

Related topics

AWS KMS · Amazon S3 · S3 Object Lock

CloudExamPro Premium

Ready to pass the AWS Solutions Architect Associate (SAA-C03)?

Stop guessing whether you’re ready. Our full-length, exam-realistic practice exams put you through the exact question style you’ll face — with a detailed explanation behind every answer, so you learn why, not just what.

  • ✓  6 full-length practice exams
  • ✓  A detailed explanation for every single question
  • ✓  Realistic, scenario-based questions — not memory dumps
  • ✓  Lifetime access, kept current for 2026

Get the SAA-C03 Practice Exams →or try 25 free questions first

Limited-time offer · ends in --Days:--Hrs:--Min:--Sec
Get Instant Access