Courseiva
Security →mediumMultiple Select

DVA-C02 Security Practice Question

A company stores sensitive data in an S3 bucket. The security team requires that all data be encrypted at rest and in transit. Which THREE measures should be implemented?

⚠ Common exam trap

It's easy for candidates to confuse client-side encryption as a bucket-level security measure, but it is an application-side implementation that does not enforce encryption at the S3 bucket level, and MFA Delete is a red herring unrelated to encryption requirements.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use HTTPS for all requests to S3

HTTPS encrypts data in transit between the client and S3 using TLS, ensuring confidentiality and integrity during transmission. This satisfies the requirement for encryption in transit, as HTTP requests would send data in plaintext.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use HTTPS for all requests to S3

    Why this is correct

    When accessing S3, using HTTPS (TLS/SSL) encrypts the data as it travels between the client and the S3 service endpoints. This prevents eavesdropping and man-in-the-middle attacks, ensuring the confidentiality and integrity of sensitive data during transmission over public networks. AWS S3 supports HTTPS by default, and it is a fundamental security best practice for protecting data in transit.

  • ✓

    Enable server-side encryption (SSE) on the S3 bucket

    Why this is correct

    Enabling server-side encryption (SSE) ensures that all objects stored within the S3 bucket are encrypted at rest on AWS's storage infrastructure. When an object is uploaded, S3 encrypts it before saving it to disk, and decrypts it automatically when retrieved. This protects sensitive data from unauthorized access even if the underlying storage media were compromised, fulfilling a critical requirement for data confidentiality.

  • ✓

    Add a bucket policy that denies requests without encryption in transit

    Why this is correct

    Implementing an S3 bucket policy to deny requests that do not use encryption in transit provides a robust enforcement mechanism for data security. This policy typically leverages the `aws:SecureTransport` condition key, setting it to `false` for denial, thereby ensuring that all interactions with the bucket *must* occur over HTTPS. This proactive measure prevents clients from inadvertently or maliciously sending unencrypted data, adding a critical layer of protection beyond client-side configuration.

  • ✗

    Use client-side encryption

    Why it's wrong here

    While client-side encryption does encrypt data before it leaves the client application, making the client responsible for encryption keys and processes, it is not a *required* solution for simply storing sensitive data securely in S3. AWS server-side encryption options (SSE-S3, SSE-KMS) provide robust, managed encryption at rest with less operational overhead for most use cases. Client-side encryption adds complexity and is typically reserved for scenarios demanding absolute control over the encryption process or specific regulatory compliance.

  • ✗

    Enable MFA Delete on the bucket

    Why it's wrong here

    Enabling MFA Delete on an S3 bucket requires a multi-factor authentication code to be provided before an object version can be permanently deleted or versioning status changed. This feature is designed to prevent accidental or unauthorized *deletion* of data, providing an additional layer of protection against data loss. However, MFA Delete does not contribute to the encryption of data, either in transit or at rest, and therefore does not address the security requirement for protecting sensitive data through encryption.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.