Enforce S3 Encryption with SSE-KMS — Bucket Policy & Key Policy
A company stores sensitive data in Amazon S3. The security team requires encryption at rest and that the encryption keys are managed by the company using AWS KMS. The data is frequently accessed by multiple AWS services. Which THREE steps should be taken to meet these requirements?
Quick Answer
The correct answer is to enable default encryption on the S3 bucket using SSE-KMS, because this satisfies the requirement for company-managed encryption keys while also ensuring that multiple AWS services can access the data. The key technical concept here is that when you enforce S3 encryption with SSE-KMS using a customer-managed key, the KMS key policy must explicitly grant decryption permissions (kms:Decrypt) to any AWS service that needs to read the objects—otherwise, even with bucket-level default encryption enabled, services like Lambda or Athena will fail with access denied errors. On the AWS Certified Data Engineer Associate DEA-C01 exam, this scenario tests your understanding of the interplay between S3 bucket policies and KMS key policies, with a common trap being that candidates assume bucket-level encryption settings alone are sufficient for cross-service access. A helpful memory tip is "bucket encrypts, key permits"—the bucket enforces encryption at rest, but the key policy is what actually allows services to decrypt and use the data.
⚠ Common exam trap
AWS often tests the distinction between enforcing encryption (bucket policy) and enabling access to encrypted data (KMS key policy), leading candidates to overlook the KMS key policy step when multiple services need to decrypt objects.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the KMS key policy to allow the necessary AWS services to use the key for decryption
The security team requires that encryption keys be managed by the company using AWS KMS, and that multiple AWS services can access the data. To allow those services to decrypt objects encrypted with a customer-managed KMS key, the KMS key policy must explicitly grant the necessary AWS services (e.g., AWS Lambda, Amazon Athena) permission to use the key for decryption (kms:Decrypt). Without this policy, even if the bucket is configured for SSE-KMS, the services will fail to read the encrypted objects.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use client-side encryption with the KMS key before uploading to S3
Why it's wrong here
Client-side encryption is not necessary; server-side encryption suffices.
- ✓
Configure the KMS key policy to allow the necessary AWS services to use the key for decryption
Why this is correct
Services must have decrypt permissions to access the encrypted objects.
- ✗
Enable default encryption on the S3 bucket using SSE-S3
Why it's wrong here
Enabling default encryption with SSE-S3 fails because it utilises keys managed by Amazon S3, directly contradicting the requirement for company-managed encryption keys via AWS KMS. The scenario explicitly demands company control over the encryption keys. This option is tempting as it provides robust encryption at rest and is a straightforward method to ensure all new objects are encrypted by default, making it suitable when Amazon-managed keys are acceptable and the company does not require direct key lifecycle management.
- ✓
Create a bucket policy that denies s3:PutObject if the object is not encrypted with SSE-KMS
Why this is correct
This ensures all objects are encrypted with the required KMS key.
- ✓
Enable default encryption on the S3 bucket using SSE-KMS
Why this is correct
SSE-KMS allows you to use your own KMS key for encryption.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This DEA-C01 question is part of Courseiva's 1,711-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
4 more ways this is tested on DEA-C01
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company is using Amazon S3 to store sensitive data. They need to ensure that all objects are encrypted at rest. Which combination of actions should be taken? (Choose TWO.)
medium- A.Enable S3 Versioning on the bucket.
- B.Enable MFA Delete on the bucket.
- C.Configure S3 Access Points with network policies.
- ✓ D.Use a bucket policy to deny PutObject requests that do not include the x-amz-server-side-encryption header.
- ✓ E.Enable default encryption on the S3 bucket.
Why D: A bucket policy that denies PutObject requests lacking the `x-amz-server-side-encryption` header enforces encryption at the time of upload, ensuring that any object written without explicit encryption headers is rejected. Option E is correct because enabling default encryption on the S3 bucket automatically applies server-side encryption (SSE-S3 or SSE-KMS) to any object uploaded without specifying encryption headers, providing a fallback that covers all objects. Together, these actions ensure that every object stored in the bucket is encrypted at rest, either by explicit client request or by default bucket settings.
Variation 2. A company uses Amazon S3 to store sensitive data. The security team requires that all data be encrypted at rest using a customer-managed key that is rotated annually. Which encryption option should be used?
easy- ✓ A.SSE-KMS (Server-Side Encryption with AWS KMS).
- B.SSE-S3 (Server-Side Encryption with S3-managed keys).
- C.Client-side encryption.
- D.SSE-C (Server-Side Encryption with Customer-Provided keys).
Why A: SSE-KMS is the correct choice because it allows you to use a customer-managed key (CMK) in AWS KMS, which you can configure to rotate automatically on an annual schedule. This satisfies the security team's requirement for encryption at rest with a key you control and rotate yearly, while still leveraging server-side encryption that integrates with S3's existing infrastructure.
Variation 3. A company uses Amazon S3 to store sensitive data. The security team wants to ensure that all objects uploaded to a specific S3 bucket are automatically encrypted at rest using server-side encryption with AWS KMS managed keys (SSE-KMS). Which bucket policy statement should be added to enforce this requirement?
medium- A.Deny put requests where 's3:x-amz-server-side-encryption' is 'aws:kms'
- ✓ B.Deny put requests where 's3:x-amz-server-side-encryption' is not 'aws:kms'
- C.Deny put requests where 's3:x-amz-server-side-encryption' is not 'AES256'
- D.Deny put requests where 's3:x-amz-server-side-encryption' is not set
Why B: It denies any S3 PUT request that does not include the `x-amz-server-side-encryption` header set to `aws:kms`, thereby enforcing SSE-KMS encryption for all objects uploaded to the bucket. This bucket policy condition ensures that only requests specifying AWS KMS-managed keys are allowed, meeting the security team's requirement for automatic encryption at rest with SSE-KMS.
Variation 4. A company is using Amazon S3 to store sensitive data. The security team requires that all data be encrypted at rest using a customer-managed AWS KMS key. The data engineer must ensure that only a specific IAM role can decrypt the data. Which policy should the data engineer attach to the KMS key?
hard- ✓ A.A KMS key policy that allows the IAM role to perform kms:Decrypt
- B.An IAM user policy that allows kms:Decrypt for the specific key
- C.An IAM policy attached to the role that allows kms:Decrypt
- D.An S3 bucket policy that denies access unless encryption is used
Why A: KMS key policies are the primary mechanism for controlling access to a customer-managed KMS key. By specifying the IAM role as a principal in the key policy and granting kms:Decrypt, you ensure that only that role can decrypt data encrypted with this key, regardless of any IAM policies that might otherwise allow broader access.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.