GregLab | Exam Prep

Design Secure Architectures

Data Protection, Encryption, and Compliance

Core

Choose access governance, encryption, keys, certificates, backup, replication, lifecycle, and compliance controls.

Aligned to the current SAA-C03 exam guide, verified August 16, 2026.

Why this matters

Data protection begins with classification and follows every stored and moving copy through access, key control, retention, and recovery. Encryption is important, but it does not replace authorization, backup, immutability, or compliance evidence.

Must Know

  • Classify data and identify residency, retention, deletion, immutability, recovery, and key-ownership requirements before choosing controls.
  • KMS integrates managed encryption keys with many AWS services and commonly uses envelope encryption. Key policies and caller permissions govern customer managed keys.
  • AWS owned keys minimize administration; AWS managed keys are service-managed in the account; customer managed KMS keys provide customer policy and lifecycle control.
  • CloudHSM provides dedicated HSM capacity with direct customer control. Choose it only when a hard cryptographic or compliance requirement exceeds KMS's managed boundary.
  • ACM manages eligible public/private certificates on supported integrations. It handles TLS identity, not data-at-rest keys.
  • Backups preserve historical recovery points; replication maintains another current copy. S3 versioning, lifecycle, replication, and Object Lock each solve different needs.
  • Artifact supplies AWS compliance reports; Audit Manager helps collect assessment evidence; operational and security services provide their own records and findings.

Compare and Distinguish

  • AWS owned vs AWS managed vs customer managed KMS keys: choose lowest administration, service-managed visibility, or customer policy/lifecycle control.
  • KMS vs CloudHSM: KMS wins for managed integration; CloudHSM wins for mandatory dedicated HSMs and direct key administration.
  • KMS vs ACM: encryption keys and TLS certificates solve different data states.
  • Backup vs replication: backup wins for point-in-time recovery; replication wins for another current copy and can support failover. Use both when required.
  • Lifecycle vs immutable retention: lifecycle transitions/expires data; Object Lock or supported vault controls address write-once retention.
  • Artifact vs Audit Manager vs Security Hub: AWS reports, assessment evidence collection, and security findings/posture are distinct.

Scenario examples

  • Scenario: S3 and RDS need customer-controlled key policies. Think: use customer managed KMS keys and narrowly authorize services and principals.
  • Scenario: Regulation mandates dedicated, customer-administered HSMs. Think: the key-control boundary points to CloudHSM despite more operations.
  • Scenario: HTTPS terminates at an ALB with managed renewal. Think: attach an eligible ACM certificate.
  • Scenario: Records must survive overwrite and remain undeletable. Think: combine version-aware recovery with immutable retention; replication alone is insufficient.

Exam traps

  • Encryption does not provide durability, retention, availability, or least privilege.
  • A replica is not automatically an independent backup; harmful changes can propagate.
  • Customer managed keys add control and responsibility, not automatic superiority.
  • CloudHSM does not provide ACM certificate lifecycle or KMS's broad managed integration.
  • Automatic rotation/renewal depends on item type and supported configuration.
  • AWS compliance reports do not make a customer workload compliant.

Key takeaways

  • Let classification choose access, encryption, key, certificate, retention, and recovery controls.
  • Use KMS for managed integration and CloudHSM only for explicit dedicated-HSM control.
  • Treat backup, replication, versioning, and immutability as complementary.
  • Collect the evidence type requested while retaining customer accountability.
How it works
  • Integrated services request authorized KMS operations and use protected data keys.
  • ACM validates ownership and manages deployment/renewal for eligible certificates on supported services.
  • AWS Backup applies centralized plans and retention across supported resources.
  • S3 lifecycle evaluates object age while replication copies eligible objects according to policy.
When to use it
  • Use customer managed KMS keys for explicit policy, separation-of-duties, cross-account, or lifecycle needs.
  • Use CloudHSM for dedicated-HSM and direct key-control requirements.
  • Use ACM for supported TLS termination.
  • Use AWS Backup for centralized cross-service protection and service-native replication for current secondary copies.
Security and governance implications
  • Separate key administration from data use where practical.
  • Protect backups with independent permissions and retention.
  • Restrict public/cross-account data access with identity and resource controls.
  • Verify exact service, Region, certificate, and compliance eligibility.
Operational and diagnostic signals
  • For decryption failures, separate key authorization, resource authorization, key state, Region, and integration.
  • For missed recovery objectives, inspect backup frequency, copy completion, dependencies, and tested restore time.
  • For certificate renewal failures, inspect eligibility, validation, and supported association.
  • For destination copy failures, verify destination-key policy and replication principals.
More detail
  • Envelope encryption protects data with a data key and protects that key under a KMS key, enabling efficient service integration.
  • Customer managed keys allow customer-defined policies and lifecycle decisions, which also creates lockout and deletion risks.
  • Cross-Region copies need destination permissions and suitable destination-Region encryption keys when customer control is required.
  • Recovery is credible only when restore behavior is tested against RPO and RTO.

Ready for the quiz?

  • When is a customer managed key justified?
  • When does CloudHSM beat KMS?
  • Why are replication and backup different?
  • What does ACM manage that KMS does not?
  • How do Artifact, Audit Manager, and Security Hub differ?

Related objectives

  • D1.3.K1
  • D1.3.K2
  • D1.3.K3
  • D1.3.K4
  • D1.3.S1
  • D1.3.S2
  • D1.3.S3
  • D1.3.S4
  • D1.3.S5
  • D1.3.S6
  • D1.3.S7

Learn more

Free AWS Certified Solutions Architect - Associate prep

Build focused SAA-C03 quizzes from skill areas, topics, and product references.

Practice with exam-style multiple-choice and multiple-response questions, score breakdowns, explanations, and a compact reference for this lane's official exam domains.

Build a quiz

Exam Weights

Exam snapshot

SAA-C03 at a glance

Category
Associate
Duration
130 minutes
Questions
65 total; 50 scored and 15 unidentified unscored
Formats
Multiple choice and multiple response
Scoring
100–1,000 scaled score; 720 minimum passing score

Quiz builder

Choose your practice set

Mode

Exam fidelity: AWS documents 65 questions in 130 minutes: 50 scored and 15 unidentified unscored, using multiple-choice and multiple-response formats. This site's practice accuracy and readiness do not reproduce AWS's 100–1,000 scaled scoring or identify unscored items. Difficulty labels describe this site's Associate-level scenario complexity, not an AWS-published question rating.

Reference

SAA-C03 topics and reference map

Study links

SAA-C03 resources