Courseiva
Security →mediumMultiple Choice

DVA-C02 Security Practice Question

A company uses AWS Organizations to manage multiple accounts. The security team wants to ensure that all S3 buckets across all accounts are encrypted with SSE-S3. What is the MOST effective way to enforce this?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use an SCP in AWS Organizations to deny s3:PutBucketEncryption unless the encryption algorithm is AES256.

AWS Organizations allows you to create service control policies (SCPs) that can be applied to all accounts in the organization. An SCP can deny the s3:PutBucketEncryption action unless the encryption algorithm is AES256 (SSE-S3). This centrally enforces encryption across all accounts. Option A is incorrect because IAM policies must be attached to each user or group individually, and they cannot be enforced across all accounts centrally. Option B is reactive (detection only) and does not prevent non-compliant actions. Option D can enforce encryption on object uploads but does not prevent configuration of bucket-level encryption settings.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create an IAM policy that denies non-SSE-S3 encryption and attach it to all users.

    Why it's wrong here

    Creating and attaching IAM policies to users is an account-specific approach. While an IAM policy can deny non-SSE-S3 encryption, it would need to be manually created and applied to relevant users or roles within *each individual member account* across the AWS Organization. This method is not scalable or centralized, making it impractical for enforcing a consistent security standard across numerous accounts and preventing root users or unconstrained roles from bypassing the policy.

  • ✗

    Use AWS Config rules to detect buckets without SSE-S3 and send alerts.

    Why it's wrong here

    AWS Config rules serve as *detective* controls, meaning they identify and report on non-compliant resources *after* they have been created or modified. While useful for auditing and alerting administrators to buckets lacking SSE-S3 encryption, Config rules do not *prevent* the initial creation of such non-compliant resources. The goal is often to prevent the misconfiguration from occurring in the first place, which Config cannot achieve.

  • ✓

    Use an SCP in AWS Organizations to deny s3:PutBucketEncryption unless the encryption algorithm is AES256.

    Why this is correct

    Service Control Policies (SCPs) in AWS Organizations provide a powerful *preventive* control mechanism that applies centrally across all member accounts within an Organizational Unit (OU) or the entire organization. By implementing an SCP to explicitly deny the s3:PutBucketEncryption action unless the encryption algorithm is AES256, it effectively prevents any account from configuring S3 buckets without the required SSE-S3 encryption, ensuring compliance at the infrastructure level.

  • ✗

    Use S3 bucket policies to deny PutObject if encryption is not SSE-S3.

    Why it's wrong here

    S3 bucket policies are resource-based policies applied directly to individual S3 buckets. While a bucket policy can effectively enforce SSE-S3 encryption for objects uploaded to that specific bucket by denying s3:PutObject without the correct headers, this approach requires manual configuration for *every single S3 bucket* across all accounts in the AWS Organization. It lacks the centralized, scalable enforcement capability necessary for a multi-account environment.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

This DVA-C02 question is part of Courseiva's 1,135-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.