Courseiva
Data Store ManagementhardMultiple SelectObjective-mapped

Enforce S3 Encryption with SSE-KMS — Bucket Policy & Key Policy

A company stores sensitive data in Amazon S3. The security team requires encryption at rest and that the encryption keys are managed by the company using AWS KMS. The data is frequently accessed by multiple AWS services. Which THREE steps should be taken to meet these requirements?

Quick Answer

The correct answer is to enable default encryption on the S3 bucket using SSE-KMS, because this satisfies the requirement for company-managed encryption keys while also ensuring that multiple AWS services can access the data. The key technical concept here is that when you enforce S3 encryption with SSE-KMS using a customer-managed key, the KMS key policy must explicitly grant decryption permissions (kms:Decrypt) to any AWS service that needs to read the objects—otherwise, even with bucket-level default encryption enabled, services like Lambda or Athena will fail with access denied errors. On the AWS Certified Data Engineer Associate DEA-C01 exam, this scenario tests your understanding of the interplay between S3 bucket policies and KMS key policies, with a common trap being that candidates assume bucket-level encryption settings alone are sufficient for cross-service access. A helpful memory tip is "bucket encrypts, key permits"—the bucket enforces encryption at rest, but the key policy is what actually allows services to decrypt and use the data.

⚠ Common exam trap

AWS often tests the distinction between enforcing encryption (bucket policy) and enabling access to encrypted data (KMS key policy), leading candidates to overlook the KMS key policy step when multiple services need to decrypt objects.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Configure the KMS key policy to allow the necessary AWS services to use the key for decryption

The security team requires that encryption keys be managed by the company using AWS KMS, and that multiple AWS services can access the data. To allow those services to decrypt objects encrypted with a customer-managed KMS key, the KMS key policy must explicitly grant the necessary AWS services (e.g., AWS Lambda, Amazon Athena) permission to use the key for decryption (kms:Decrypt). Without this policy, even if the bucket is configured for SSE-KMS, the services will fail to read the encrypted objects.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Use client-side encryption with the KMS key before uploading to S3

    Why it's wrong here

    Client-side encryption is not necessary; server-side encryption suffices.

  • Configure the KMS key policy to allow the necessary AWS services to use the key for decryption

    Why this is correct

    Services must have decrypt permissions to access the encrypted objects.

  • Enable default encryption on the S3 bucket using SSE-S3

    Why it's wrong here

    Enabling default encryption with SSE-S3 fails because it utilises keys managed by Amazon S3, directly contradicting the requirement for company-managed encryption keys via AWS KMS. The scenario explicitly demands company control over the encryption keys. This option is tempting as it provides robust encryption at rest and is a straightforward method to ensure all new objects are encrypted by default, making it suitable when Amazon-managed keys are acceptable and the company does not require direct key lifecycle management.

  • Create a bucket policy that denies s3:PutObject if the object is not encrypted with SSE-KMS

    Why this is correct

    This ensures all objects are encrypted with the required KMS key.

  • Enable default encryption on the S3 bucket using SSE-KMS

    Why this is correct

    SSE-KMS allows you to use your own KMS key for encryption.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This DEA-C01 question is part of Courseiva's 1,711-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

4 more ways this is tested on DEA-C01

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company is using Amazon S3 to store sensitive data. They need to ensure that all objects are encrypted at rest. Which combination of actions should be taken? (Choose TWO.)

medium
  • A.Enable S3 Versioning on the bucket.
  • B.Enable MFA Delete on the bucket.
  • C.Configure S3 Access Points with network policies.
  • D.Use a bucket policy to deny PutObject requests that do not include the x-amz-server-side-encryption header.
  • E.Enable default encryption on the S3 bucket.

Why D: A bucket policy that denies PutObject requests lacking the `x-amz-server-side-encryption` header enforces encryption at the time of upload, ensuring that any object written without explicit encryption headers is rejected. Option E is correct because enabling default encryption on the S3 bucket automatically applies server-side encryption (SSE-S3 or SSE-KMS) to any object uploaded without specifying encryption headers, providing a fallback that covers all objects. Together, these actions ensure that every object stored in the bucket is encrypted at rest, either by explicit client request or by default bucket settings.

Variation 2. A company uses Amazon S3 to store sensitive data. The security team requires that all data be encrypted at rest using a customer-managed key that is rotated annually. Which encryption option should be used?

easy
  • A.SSE-KMS (Server-Side Encryption with AWS KMS).
  • B.SSE-S3 (Server-Side Encryption with S3-managed keys).
  • C.Client-side encryption.
  • D.SSE-C (Server-Side Encryption with Customer-Provided keys).

Why A: SSE-KMS is the correct choice because it allows you to use a customer-managed key (CMK) in AWS KMS, which you can configure to rotate automatically on an annual schedule. This satisfies the security team's requirement for encryption at rest with a key you control and rotate yearly, while still leveraging server-side encryption that integrates with S3's existing infrastructure.

Variation 3. A company uses Amazon S3 to store sensitive data. The security team wants to ensure that all objects uploaded to a specific S3 bucket are automatically encrypted at rest using server-side encryption with AWS KMS managed keys (SSE-KMS). Which bucket policy statement should be added to enforce this requirement?

medium
  • A.Deny put requests where 's3:x-amz-server-side-encryption' is 'aws:kms'
  • B.Deny put requests where 's3:x-amz-server-side-encryption' is not 'aws:kms'
  • C.Deny put requests where 's3:x-amz-server-side-encryption' is not 'AES256'
  • D.Deny put requests where 's3:x-amz-server-side-encryption' is not set

Why B: It denies any S3 PUT request that does not include the `x-amz-server-side-encryption` header set to `aws:kms`, thereby enforcing SSE-KMS encryption for all objects uploaded to the bucket. This bucket policy condition ensures that only requests specifying AWS KMS-managed keys are allowed, meeting the security team's requirement for automatic encryption at rest with SSE-KMS.

Variation 4. A company is using Amazon S3 to store sensitive data. The security team requires that all data be encrypted at rest using a customer-managed AWS KMS key. The data engineer must ensure that only a specific IAM role can decrypt the data. Which policy should the data engineer attach to the KMS key?

hard
  • A.A KMS key policy that allows the IAM role to perform kms:Decrypt
  • B.An IAM user policy that allows kms:Decrypt for the specific key
  • C.An IAM policy attached to the role that allows kms:Decrypt
  • D.An S3 bucket policy that denies access unless encryption is used

Why A: KMS key policies are the primary mechanism for controlling access to a customer-managed KMS key. By specifying the IAM role as a principal in the key policy and granting kms:Decrypt, you ensure that only that role can decrypt data encrypted with this key, regardless of any IAM policies that might otherwise allow broader access.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.