S3 can encrypt your objects at rest, and the exam tests that you know the options and who controls the keys. Encryption in transit uses HTTPS; encryption at rest uses one of several server-side options.
The encryption options
SSE-S3 — S3 manages the keys for you (simplest). SSE-KMS — keys managed in AWS KMS, giving you rotation, policies, and CloudTrail auditing of key use. SSE-C — you supply and manage the keys yourself. Client-side encryption means you encrypt before upload. When the scenario needs audit trails and control over keys, that’s SSE-KMS.
Test yourself
A company must encrypt S3 objects at rest and needs an audit trail of every time the encryption key is used, plus control over key rotation. Which option?
- SSE-S3
- SSE-KMS
- No encryption, use a bucket policy
- SSE-C
👉 Click to reveal the answer & explanation
Correct answer: B. SSE-KMS uses KMS-managed keys with rotation, key policies, and CloudTrail logging of key usage — the audit trail requirement. SSE-S3 (A) gives no key-level control or audit; a bucket policy (C) isn’t encryption; SSE-C (D) offloads key management to you without KMS auditing.
Related topics
AWS KMS · Amazon S3 · S3 Object Lock
Ready to pass the AWS Solutions Architect Associate (SAA-C03)?
Stop guessing whether you’re ready. Our full-length, exam-realistic practice exams put you through the exact question style you’ll face — with a detailed explanation behind every answer, so you learn why, not just what.
- ✓ 6 full-length practice exams
- ✓ A detailed explanation for every single question
- ✓ Realistic, scenario-based questions — not memory dumps
- ✓ Lifetime access, kept current for 2026
Get the SAA-C03 Practice Exams →or try 25 free questions first