DVA-C02 Development with AWS Services Practice Question
A company is using Amazon S3 to store sensitive documents. They must encrypt all objects at rest. Which TWO methods can be used to enforce server-side encryption? (Choose TWO.)
⚠ Common exam trap
Candidates often confuse client-side encryption (Option E) with server-side encryption. Additionally, while IAM policies (Option C) can restrict user actions, denying 'all S3 actions' unless encryption is specified is incorrect because read actions (like GetObject) or metadata actions (like ListBucket) do not require encryption headers.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set a bucket policy that denies PutObject if x-amz-server-side-encryption header is not present.
Option A is correct because a bucket policy can include a Deny statement on s3:PutObject with a condition such as StringNotEquals on s3:x-amz-server-side-encryption (or its absence via Null), which blocks any upload that does not request server-side encryption with the required algorithm (for example, AES256 or aws:kms). Option B is correct because enabling default bucket encryption (SSE-S3, SSE-KMS, or DSSE-KMS) causes Amazon S3 to automatically encrypt every object at rest on upload, even when the request does not include the x-amz-server-side-encryption header, thereby enforcing encryption at rest. Option C is not appropriate because an IAM policy denying all S3 actions unless encryption is specified is overly broad and does not itself enforce encryption on PutObject in the precise, header-based way a bucket policy condition does. Option D is wrong because an SQS queue policy governs access to an SQS queue, not to S3 objects, and has no effect on S3 server-side encryption. Option E is wrong because client-side encryption encrypts data before it reaches S3 and is not a server-side encryption enforcement method.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Set a bucket policy that denies PutObject if x-amz-server-side-encryption header is not present.
Why this is correct
Setting a bucket policy allows you to define granular permissions and conditions for all principals interacting with the S3 bucket. By using a `Deny` statement with a condition that checks for the absence of the `s3:x-amz-server-side-encryption` header during a `s3:PutObject` action, you can effectively enforce that all new objects uploaded to the bucket must be encrypted at rest using server-side encryption. This ensures compliance across all uploads, regardless of the uploader's individual IAM permissions.
- ✓
Enable default encryption on the S3 bucket.
Why this is correct
Enabling default encryption on an S3 bucket automatically encrypts all new objects uploaded to that bucket using either SSE-S3 (Amazon S3-managed keys) or SSE-KMS (AWS Key Management Service keys). This is a straightforward and robust method to ensure that all data stored in the bucket is encrypted at rest without requiring clients to specify encryption headers during upload, simplifying client-side implementation while maintaining security.
- ✗
Attach an IAM policy that denies all S3 actions unless encryption is specified.
Why it's wrong here
IAM policies primarily control *who* can perform *what* actions on *which* resources, defining permissions for users or roles. While an IAM policy can include conditions, it cannot effectively enforce a specific HTTP header like `x-amz-server-side-encryption` for all `PutObject` operations across an entire bucket. A bucket policy is the correct mechanism to enforce such a requirement universally on the bucket itself, applying to all principals attempting to upload objects.
- ✗
Configure an SQS queue policy to require encryption.
Why it's wrong here
Amazon SQS (Simple Queue Service) is a message queuing service used for decoupling and scaling microservices, distributed systems, and serverless applications. SQS queue policies govern access to the queue and its messages, defining who can send or receive messages. SQS has no direct integration or capability to enforce or manage the encryption of objects stored within an Amazon S3 bucket, making it irrelevant for this purpose.
- ✗
Use client-side encryption before uploading objects.
Why it's wrong here
Client-side encryption involves encrypting data on the client's side *before* it is sent to S3, meaning the data arrives at S3 already encrypted. While this provides strong security, it is distinct from server-side encryption, where S3 itself performs the encryption *after* receiving the unencrypted data. The question implies a need for S3's managed encryption features, and client-side encryption shifts the key management burden entirely to the client, which may not align with the company's operational requirements for server-side managed encryption.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.