DVA-C02 Security • Set 28
DVA-C02 Security Practice Test 28 — 15 questions with explanations. Free, no signup.
A company has a multi-account AWS environment using AWS Organizations. The security team wants to enforce that all S3 buckets across all accounts are encrypted using SSE-KMS with a specific KMS key from the central security account. They also want to prevent any unencrypted bucket creation. A developer in the development account creates a new S3 bucket and enables default encryption using SSE-S3. The bucket creation succeeds, but the security team wants to prevent this. The developer argues that the bucket still encrypts data at rest. Compliance requires SSE-KMS only. What should the security team do to enforce this policy across all accounts?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.