DVA-C02 Security Practice Question
A company uses AWS Organizations to manage multiple accounts. The security team wants to ensure that all S3 buckets across all accounts are encrypted with SSE-S3. What is the MOST effective way to enforce this?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use an SCP in AWS Organizations to deny s3:PutBucketEncryption unless the encryption algorithm is AES256.
AWS Organizations allows you to create service control policies (SCPs) that can be applied to all accounts in the organization. An SCP can deny the s3:PutBucketEncryption action unless the encryption algorithm is AES256 (SSE-S3). This centrally enforces encryption across all accounts. Option A is incorrect because IAM policies must be attached to each user or group individually, and they cannot be enforced across all accounts centrally. Option B is reactive (detection only) and does not prevent non-compliant actions. Option D can enforce encryption on object uploads but does not prevent configuration of bucket-level encryption settings.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create an IAM policy that denies non-SSE-S3 encryption and attach it to all users.
Why it's wrong here
Creating and attaching IAM policies to users is an account-specific approach. While an IAM policy can deny non-SSE-S3 encryption, it would need to be manually created and applied to relevant users or roles within *each individual member account* across the AWS Organization. This method is not scalable or centralized, making it impractical for enforcing a consistent security standard across numerous accounts and preventing root users or unconstrained roles from bypassing the policy.
- ✗
Use AWS Config rules to detect buckets without SSE-S3 and send alerts.
Why it's wrong here
AWS Config rules serve as *detective* controls, meaning they identify and report on non-compliant resources *after* they have been created or modified. While useful for auditing and alerting administrators to buckets lacking SSE-S3 encryption, Config rules do not *prevent* the initial creation of such non-compliant resources. The goal is often to prevent the misconfiguration from occurring in the first place, which Config cannot achieve.
- ✓
Use an SCP in AWS Organizations to deny s3:PutBucketEncryption unless the encryption algorithm is AES256.
Why this is correct
Service Control Policies (SCPs) in AWS Organizations provide a powerful *preventive* control mechanism that applies centrally across all member accounts within an Organizational Unit (OU) or the entire organization. By implementing an SCP to explicitly deny the s3:PutBucketEncryption action unless the encryption algorithm is AES256, it effectively prevents any account from configuring S3 buckets without the required SSE-S3 encryption, ensuring compliance at the infrastructure level.
- ✗
Use S3 bucket policies to deny PutObject if encryption is not SSE-S3.
Why it's wrong here
S3 bucket policies are resource-based policies applied directly to individual S3 buckets. While a bucket policy can effectively enforce SSE-S3 encryption for objects uploaded to that specific bucket by denying s3:PutObject without the correct headers, this approach requires manual configuration for *every single S3 bucket* across all accounts in the AWS Organization. It lacks the centralized, scalable enforcement capability necessary for a multi-account environment.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
This DVA-C02 question is part of Courseiva's 1,135-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.