DOP-C02 Security and Compliance Practice Question
A company is using Amazon S3 to store sensitive data. The security team mandates that all data must be encrypted at rest using server-side encryption with AWS Key Management Service (SSE-KMS). The DevOps engineer must ensure that any new objects uploaded to the bucket are automatically encrypted. What should the engineer do?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable default encryption on the S3 bucket and select AWS-KMS as the encryption method.
Enabling default encryption on the S3 bucket with SSE-KMS ensures that all objects uploaded to the bucket are automatically encrypted at rest with AWS KMS. Option A is incorrect because CORS is for cross-origin requests and does not affect encryption. Option B is incorrect because while a bucket policy can enforce encryption headers, it does not provide default encryption; it only denies requests without the header, and default encryption is a simpler and more reliable method. Option D is incorrect because versioning does not encrypt data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable CORS on the bucket to allow encrypted uploads.
Why it's wrong here
CORS (Cross-Origin Resource Sharing) is a browser security feature that controls whether web applications from one origin can make HTTP requests to resources in another origin; it has absolutely no effect on how S3 encrypts data at rest or in transit. Enabling CORS on a bucket merely permits browsers to make cross-origin calls, such as direct uploads from a web app, but it does not add, enforce, or influence encryption in any way. Therefore, it cannot ensure that sensitive data is encrypted with KMS or any other encryption method.
- ✗
Apply a bucket policy that denies PutObject unless the request includes the x-amz-server-side-encryption header with aws:kms.
Why it's wrong here
A bucket policy that denies PutObject unless the request includes the x-amz-server-side-encryption header with value aws:kms enforces a requirement: every upload must explicitly declare KMS encryption, or the request is rejected. However, it does not automatically encrypt objects that lack the header; it simply denies them, which can cause failures for clients that do not send the header. Additionally, it provides no encryption for objects already stored in the bucket, and it is an enforcement mechanism rather than a method of automatically applying encryption, making it less transparent than default encryption.
- ✓
Enable default encryption on the S3 bucket and select AWS-KMS as the encryption method.
Why this is correct
Enabling default encryption on an S3 bucket with AWS-KMS selected ensures that every new object is automatically encrypted at rest using SSE-KMS, regardless of whether the upload request includes any encryption headers. This uses envelope encryption with a customer-managed KMS key, offering centralized key management, separate permissions for key access, and an audit trail of key usage. It is the correct approach because it is a direct, bucket-level setting that protects sensitive data without requiring client changes or policy-based request rejections.
- ✗
Enable S3 Versioning to protect encrypted objects.
Why it's wrong here
S3 Versioning maintains multiple versions of each object, which protects against accidental deletion or overwrite by allowing you to recover earlier states, but it has no bearing on encryption. If an object is uploaded unencrypted, every version of that object remains unencrypted; enabling versioning after the fact does not encrypt existing or future objects automatically. Encryption is an independent attribute of each object version, and versioning alone cannot satisfy a requirement to protect sensitive data at rest.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.