Full AWS Practitioner Certification Question

A medical research facility is planning to store sensitive patient data, including confidential health metrics, in Amazon S3. Regulatory guidelines require the encryption of all protected health information (PHI) both during transmission and while at rest. Additionally, the compliance office within the organization must retain full administrative control over the encryption key used for protecting the stored data. What is the most appropriate configuration to fulfill these requirements?