DOP-C02 Security and Compliance • Set 18
DOP-C02 Security and Compliance Practice Test 18 — 15 questions with explanations. Free, no signup.
A company has a multi-account AWS environment using AWS Organizations. The security team wants to enforce that all S3 buckets in all accounts are encrypted with SSE-S3. They plan to use an SCP to deny the creation of unencrypted buckets. The DevOps engineer writes an SCP with a Deny effect for s3:PutBucketEncryption without a condition. However, when testing, an administrator in a member account is able to create a bucket without encryption. The engineer checks CloudTrail and sees that the bucket was created with a PutBucket call that did not include the x-amz-server-side-encryption header. What is the most likely reason the SCP did not prevent this?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.