Courseiva
Security →mediumMultiple Select

DVA-C02 Security Practice Question

A company uses AWS Organizations with multiple accounts. The security team wants to enforce that all S3 buckets are encrypted with AES-256 (SSE-S3) and that no public access is allowed. Which TWO methods can be used to enforce these requirements across all accounts? (Choose TWO.)

⚠ Common exam trap

It's easy for candidates to confuse SCPs with IAM policies, thinking SCPs can grant permissions (they only deny), or they assume CloudTrail or Trusted Advisor can enforce security requirements when they are only detective or advisory tools.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use AWS Config rules with automatic remediation to detect and fix non-compliant buckets.

AWS Config rules can evaluate S3 bucket configurations against desired settings (e.g., encryption enabled, public access blocked) and trigger automatic remediation via AWS Systems Manager Automation documents to fix non-compliant buckets. This provides continuous enforcement across all accounts in the organization without manual intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use AWS Config rules with automatic remediation to detect and fix non-compliant buckets.

    Why this is correct

    AWS Config rules continuously evaluate S3 buckets against predefined or custom compliance standards, such as requiring server-side encryption or blocking public access. When a non-compliant bucket is detected, Config can automatically trigger remediation actions, like applying a default encryption policy or enabling S3 Block Public Access, ensuring ongoing adherence to security policies across all accounts where the rule is deployed. This proactive approach ensures that any newly created or modified non-compliant buckets are swiftly brought into compliance without manual intervention.

  • ✗

    Attach an IAM policy to all IAM users in each account that denies unencrypted operations.

    Why it's wrong here

    Attaching IAM policies to individual IAM users within each account is insufficient because it only restricts those specific users and does not apply to service roles, the root user, or other principals. Furthermore, IAM policies primarily control *who can perform an action*, not necessarily *how the action is performed* (e.g., forcing encryption on *all* PutObject requests without explicit bucket policies). This approach would require extensive, decentralized management across numerous accounts and still leave many potential vectors for non-compliant S3 operations.

  • ✓

    Use an SCP in the root organizational unit to deny 's3:PutBucketPublicAccessBlock' and enforce encryption settings.

    Why this is correct

    A Service Control Policy (SCP) applied at the root organizational unit provides a powerful, preventative guardrail by explicitly denying actions that could compromise S3 bucket security, such as `s3:PutBucketPublicAccessBlock` if the intent is to enforce it. SCPs define the maximum available permissions for all IAM users and roles in affected accounts, effectively preventing any account administrator from disabling critical security features or creating buckets without required encryption settings, thereby enforcing a baseline security posture across the entire organization. This centralized control ensures consistent compliance.

  • ✗

    Enable AWS CloudTrail to log all S3 API calls and send alerts.

    Why it's wrong here

    While AWS CloudTrail is essential for auditing and monitoring API activity, logging S3 API calls and sending alerts is a reactive measure that detects non-compliant actions *after* they have occurred. CloudTrail provides visibility into who did what, when, and from where, but it does not inherently prevent users or services from performing unencrypted operations or creating non-compliant buckets. Therefore, it cannot enforce encryption settings or prevent public access proactively; it only notifies of violations post-facto.

  • ✗

    Use AWS Trusted Advisor to check for unencrypted buckets.

    Why it's wrong here

    AWS Trusted Advisor provides recommendations and best practice checks, including identifying unencrypted S3 buckets, but it is a diagnostic tool that offers advice rather than enforcement. It performs periodic checks and highlights potential issues, but it does not have the capability to prevent the creation of non-compliant resources or automatically remediate existing ones. Relying solely on Trusted Advisor would require manual intervention to address each identified issue, making it unsuitable for automated, organization-wide enforcement.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.