Courseiva
Security and Compliance →easyMultiple Choice

DOP-C02 Security and Compliance Practice Question

A company is using Amazon S3 to store sensitive data. The security team mandates that all data must be encrypted at rest using server-side encryption with AWS Key Management Service (SSE-KMS). The DevOps engineer must ensure that any new objects uploaded to the bucket are automatically encrypted. What should the engineer do?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable default encryption on the S3 bucket and select AWS-KMS as the encryption method.

Enabling default encryption on the S3 bucket with SSE-KMS ensures that all objects uploaded to the bucket are automatically encrypted at rest with AWS KMS. Option A is incorrect because CORS is for cross-origin requests and does not affect encryption. Option B is incorrect because while a bucket policy can enforce encryption headers, it does not provide default encryption; it only denies requests without the header, and default encryption is a simpler and more reliable method. Option D is incorrect because versioning does not encrypt data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable CORS on the bucket to allow encrypted uploads.

    Why it's wrong here

    CORS (Cross-Origin Resource Sharing) is a browser security feature that controls whether web applications from one origin can make HTTP requests to resources in another origin; it has absolutely no effect on how S3 encrypts data at rest or in transit. Enabling CORS on a bucket merely permits browsers to make cross-origin calls, such as direct uploads from a web app, but it does not add, enforce, or influence encryption in any way. Therefore, it cannot ensure that sensitive data is encrypted with KMS or any other encryption method.

  • ✗

    Apply a bucket policy that denies PutObject unless the request includes the x-amz-server-side-encryption header with aws:kms.

    Why it's wrong here

    A bucket policy that denies PutObject unless the request includes the x-amz-server-side-encryption header with value aws:kms enforces a requirement: every upload must explicitly declare KMS encryption, or the request is rejected. However, it does not automatically encrypt objects that lack the header; it simply denies them, which can cause failures for clients that do not send the header. Additionally, it provides no encryption for objects already stored in the bucket, and it is an enforcement mechanism rather than a method of automatically applying encryption, making it less transparent than default encryption.

  • ✓

    Enable default encryption on the S3 bucket and select AWS-KMS as the encryption method.

    Why this is correct

    Enabling default encryption on an S3 bucket with AWS-KMS selected ensures that every new object is automatically encrypted at rest using SSE-KMS, regardless of whether the upload request includes any encryption headers. This uses envelope encryption with a customer-managed KMS key, offering centralized key management, separate permissions for key access, and an audit trail of key usage. It is the correct approach because it is a direct, bucket-level setting that protects sensitive data without requiring client changes or policy-based request rejections.

  • ✗

    Enable S3 Versioning to protect encrypted objects.

    Why it's wrong here

    S3 Versioning maintains multiple versions of each object, which protects against accidental deletion or overwrite by allowing you to recover earlier states, but it has no bearing on encryption. If an object is uploaded unencrypted, every version of that object remains unencrypted; enabling versioning after the fact does not encrypt existing or future objects automatically. Encryption is an independent attribute of each object version, and versioning alone cannot satisfy a requirement to protect sensitive data at rest.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.