Your organization requires encryption for sensitive data stored in Amazon S3. The security policy mandates that the organization manages its own encryption keys and that encryption must occur before the data leaves the organization's premises. Which encryption method aligns most closely with these requirements?
Server-side encryption with Amazon S3-managed keys (SSE-S3)
Server-side encryption with customer-provided keys (SSE-C)
Server-side encryption with AWS KMS-managed keys (SSE-KMS)
Client-side encryption with a customer-managed encryption key