DVA-C02 Security Practice Question
A company stores sensitive data in an S3 bucket. The security team requires that all data be encrypted at rest and in transit. Which THREE measures should be implemented?
⚠ Common exam trap
It's easy for candidates to confuse client-side encryption as a bucket-level security measure, but it is an application-side implementation that does not enforce encryption at the S3 bucket level, and MFA Delete is a red herring unrelated to encryption requirements.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use HTTPS for all requests to S3
HTTPS encrypts data in transit between the client and S3 using TLS, ensuring confidentiality and integrity during transmission. This satisfies the requirement for encryption in transit, as HTTP requests would send data in plaintext.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use HTTPS for all requests to S3
Why this is correct
When accessing S3, using HTTPS (TLS/SSL) encrypts the data as it travels between the client and the S3 service endpoints. This prevents eavesdropping and man-in-the-middle attacks, ensuring the confidentiality and integrity of sensitive data during transmission over public networks. AWS S3 supports HTTPS by default, and it is a fundamental security best practice for protecting data in transit.
- ✓
Enable server-side encryption (SSE) on the S3 bucket
Why this is correct
Enabling server-side encryption (SSE) ensures that all objects stored within the S3 bucket are encrypted at rest on AWS's storage infrastructure. When an object is uploaded, S3 encrypts it before saving it to disk, and decrypts it automatically when retrieved. This protects sensitive data from unauthorized access even if the underlying storage media were compromised, fulfilling a critical requirement for data confidentiality.
- ✓
Add a bucket policy that denies requests without encryption in transit
Why this is correct
Implementing an S3 bucket policy to deny requests that do not use encryption in transit provides a robust enforcement mechanism for data security. This policy typically leverages the `aws:SecureTransport` condition key, setting it to `false` for denial, thereby ensuring that all interactions with the bucket *must* occur over HTTPS. This proactive measure prevents clients from inadvertently or maliciously sending unencrypted data, adding a critical layer of protection beyond client-side configuration.
- ✗
Use client-side encryption
Why it's wrong here
While client-side encryption does encrypt data before it leaves the client application, making the client responsible for encryption keys and processes, it is not a *required* solution for simply storing sensitive data securely in S3. AWS server-side encryption options (SSE-S3, SSE-KMS) provide robust, managed encryption at rest with less operational overhead for most use cases. Client-side encryption adds complexity and is typically reserved for scenarios demanding absolute control over the encryption process or specific regulatory compliance.
- ✗
Enable MFA Delete on the bucket
Why it's wrong here
Enabling MFA Delete on an S3 bucket requires a multi-factor authentication code to be provided before an object version can be permanently deleted or versioning status changed. This feature is designed to prevent accidental or unauthorized *deletion* of data, providing an additional layer of protection against data loss. However, MFA Delete does not contribute to the encryption of data, either in transit or at rest, and therefore does not address the security requirement for protecting sensitive data through encryption.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.