Objective 1.3

SAA-C03

Determine appropriate data security controls.

Objective 1.3 sits in Design Secure Architectures, which carries 30% of the Solutions Architect Associate exam. The questions below are original, written from the official objective title above, and each explanation cites the Amazon Web Services (AWS) page it rests on.

Objective title verbatim from the official objectives. Amazon Web Services (AWS) exam page ↗

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

1-3Design Secure Architectures

An auditor examines a bucket created last week. Nobody on the team set an encryption configuration, and objects have been uploaded daily since. What protects those objects at rest?

Only objects uploaded over TLS are encryptedTLS covers the wire. What happens on disk is decided by the bucket configuration rather than by the transport the client used.
Objects stay unencrypted until you enable itThat held before the base level reached every bucket. There is nothing left to turn on for new uploads.
SSE-KMS under the aws/s3 managed keyThat type is available and is what you pick when you want a key policy of your own and a usage trail. It is not the baseline.
SSE-S3 encryption on every object uploadedCorrect · your answerCorrect. New uploads are covered by keys the service holds, with no action from the bucket owner.

Correct.

Checked against docs.aws.amazon.com, August 2026

Concept

A protection that somebody has to switch on protects nobody. Object storage now applies a baseline as it writes, so the open question is which key material is used, never whether anything happened at all.

Why D

Every bucket carries a base level configuration and each new upload is written encrypted at no extra cost. A team that wants different key material changes the bucket default or names a type per request.

Source

All Amazon S3 buckets have encryption configured by default, and all new objects that are uploaded to an S3 bucket are automatically encrypted at rest. Server-side encryption with Amazon S3 managed keys (SSE-S3) is the default encryption configuration for every bucket in Amazon S3…

AWS docs: Server-side encryption for S3 objects, checked August 2026
#s3#encryption#sse-s3#default-encryption

Now you: objective 1.3 questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

1-3Design Secure Architectures

Compliance requires a team to control who may decrypt a bucket's objects and to see each key use in CloudTrail. Which encryption option fits?

Sample question 2 of 3

1-3Design Secure Architectures

A production RDS instance runs unencrypted, and compliance now requires encryption at rest. Which sequence gets your team there?

Sample question 3 of 3

1-3Design Secure Architectures

An engineer disables the KMS key behind an encrypted RDS instance that has backups turned on. What happens to the instance?

Full Solutions Architect Associate question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Design Secure Architectures