Courseiva
Security →mediumMultiple Choice

DVA-C02 Security Practice Question

A company is using an S3 bucket to store sensitive data. They want to ensure that all objects uploaded to the bucket are encrypted at rest using server-side encryption with AWS KMS (SSE-KMS). What is the most secure way to enforce this?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a bucket policy that denies PutObject unless the x-amz-server-side-encryption header is set to aws:kms.

A bucket policy that denies PutObject unless the x-amz-server-side-encryption header equals aws:kms actively rejects any upload that does not explicitly request SSE-KMS, making it the strongest enforcement mechanism for this scenario. This policy-level Deny cannot be bypassed by users or roles, and it ensures every object is encrypted with AWS KMS keys rather than weaker or default encryption. Option A only sets a default that can be overridden by an uploader specifying a different encryption method, so it does not truly enforce SSE-KMS. Option B is too vague because it does not specify the required encryption type, allowing SSE-S3 or other algorithms, and Option D addresses public access, not encryption at rest.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable default encryption on the bucket with SSE-KMS.

    Why it's wrong here

    Enabling default encryption on an S3 bucket with SSE-KMS provides a baseline for new object uploads. However, this setting can be explicitly overridden by a client during the PutObject operation. If an uploader specifies x-amz-server-side-encryption: NONE or omits the encryption header entirely, the object will be stored unencrypted, failing to meet the requirement for sensitive data. Therefore, it does not strictly enforce encryption.

  • ✗

    Create a bucket policy that denies PutObject without encryption.

    Why it's wrong here

    A generic bucket policy statement that "denies PutObject without encryption" is insufficient because S3 policies require specific condition keys to evaluate encryption status. Without explicitly checking for headers like s3:x-amz-server-side-encryption or s3:x-amz-server-side-encryption-aws-kms-key-id, the policy lacks the necessary criteria to identify and block unencrypted uploads. Such a broad statement would not effectively enforce encryption.

  • ✓

    Create a bucket policy that denies PutObject unless the x-amz-server-side-encryption header is set to aws:kms.

    Why this is correct

    This bucket policy precisely enforces server-side encryption using AWS KMS for all new objects uploaded to the bucket. By including a Condition that checks StringEquals on the s3:x-amz-server-side-encryption key with a value of aws:kms, any PutObject request not specifying SSE-KMS will be explicitly denied. This ensures that all sensitive data at rest is encrypted with customer-managed or AWS-managed KMS keys, providing robust protection.

  • ✗

    Enable S3 Block Public Access on the bucket.

    Why it's wrong here

    Enabling S3 Block Public Access is a critical security measure designed to prevent public access to S3 buckets and objects, either through ACLs, bucket policies, or public access points. While essential for overall security, it focuses solely on access control and does not, in any way, enforce or guarantee that objects stored within the bucket are encrypted at rest. It addresses a different security concern than data encryption.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on DVA-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company has an S3 bucket that stores sensitive data. They want to ensure that any object uploaded to the bucket is automatically encrypted with server-side encryption using AWS KMS (SSE-KMS). They also want to deny any uploads that do not specify the correct encryption. Which bucket policy condition should be used to enforce this requirement?

medium
  • ✓ A.s3:x-amz-server-side-encryption equals aws:kms
  • B.s3:x-amz-server-side-encryption equals AES256
  • C.s3:x-amz-server-side-encryption-aws-kms-key-id equals a specific key ARN
  • D.aws:SecureTransport equals true

Why A: The condition `s3:x-amz-server-side-encryption equals aws:kms` enforces that any PUT request to the S3 bucket must include the `x-amz-server-side-encryption` header set to `aws:kms`, which triggers SSE-KMS encryption. This policy condition ensures that objects uploaded without specifying SSE-KMS are denied, meeting the requirement to automatically encrypt all uploaded objects with AWS KMS.

Variation 2. A company is using an S3 bucket to store sensitive documents. They need to ensure that all objects are encrypted at rest using server-side encryption with AWS KMS. The bucket policy must enforce encryption by denying uploads that do not specify the required encryption. Which bucket policy statement should be added?

medium
  • ✓ A.Condition: StringNotEquals: 's3:x-amz-server-side-encryption': 'aws:kms'
  • B.Condition: StringEquals: 's3:x-amz-server-side-encryption-aws:kms': 'true'
  • C.Condition: Null: 's3:x-amz-server-side-encryption': 'true'
  • D.Condition: StringNotEquals: 's3:x-amz-server-side-encryption': 'AES256'

Why A: The bucket policy uses the `s3:x-amz-server-side-encryption` condition key with `StringNotEquals` to deny any upload where the header does not specify `aws:kms`. This ensures that only objects encrypted with AWS KMS (SSE-KMS) are allowed, enforcing server-side encryption at rest. The `Deny` effect combined with this condition blocks requests that either omit the encryption header or specify a different value like `AES256`.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.