DOP-C02 Security and Compliance Practice Question
A company is using AWS Organizations with multiple accounts. The security team wants to enforce that all S3 buckets have encryption enabled. They need a preventive control that applies to all current and future accounts. Which approach should they use?
⚠ Common exam trap
It's easy for candidates to confuse detective controls (like AWS Config or CloudTrail) with preventive controls (like SCPs), or assume that IAM policies applied per account are sufficient for organization-wide enforcement, failing to recognize that SCPs are the only mechanism that applies uniformly to all accounts, including future ones.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a service control policy (SCP) in the Organizations root to deny PutBucketEncryption actions when encryption settings do not include AES256 or aws:kms.
A service control policy (SCP) applied at the Organizations root can deny the creation or modification of S3 buckets that do not have encryption enabled, specifically requiring AES256 or aws:kms. This is a preventive control that applies to all current and future accounts in the organization, as SCPs are inherited by all accounts and cannot be overridden by IAM policies within those accounts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use a service control policy (SCP) in the Organizations root to deny PutBucketEncryption actions when encryption settings do not include AES256 or aws:kms.
Why this is correct
A service control policy (SCP) attached at the Organizations root is a preventive guardrail that applies to every account in the organization, including accounts created later. By using the s3:x-amz-server-side-encryption condition key with values AES256 or aws:kms, you can deny any PutBucketEncryption call that attempts to use a different encryption type, such as SSE-C or no encryption. This works because SCPs filter permitted API actions before they reach IAM, and they cannot be overridden by account administrators, making them the correct way to enforce encryption settings organization-wide.
- ✗
Use AWS Config rules to detect unencrypted buckets and automatically apply encryption using a remediation action.
Why it's wrong here
AWS Config rules are detective and reactive: they evaluate resource state after a bucket is created or modified, and the automatic remediation action (for example, an SSM automation document) runs only after the non-compliant bucket already exists. During the time between the prohibited action and the remediation, the bucket is unencrypted, violating the intended security posture. Config rules also require per-account or per-region setup and do not stop the original PutBucketEncryption call, so they are not a genuine preventive control.
- ✗
Enable AWS CloudTrail to log all S3 API calls and send alerts when non-compliant buckets are created.
Why it's wrong here
CloudTrail records API activity but has no ability to block or modify an S3 request. When a non-compliant bucket is created, CloudTrail delivers the event to the configured S3 bucket or CloudWatch Logs after the fact, and any alarm triggered from the event simply alerts you to a violation that has already succeeded. This is a detective control that helps with auditing and forensics, but it does not enforce encryption requirements at the moment the API call is made.
- ✗
Create an IAM policy in each account that denies PutBucketEncryption unless encryption is enabled.
Why it's wrong here
IAM policies are scoped to individual accounts and identities, so applying deny statements to every account requires manual distribution and must be repeated whenever a new member account joins the organization. Account administrators with IAM permissions could also modify or remove these policies locally, which weakens the control. In the context of AWS Organizations, the service control policy at the root is the appropriate mechanism because it is centrally managed, continuously enforced, and automatically applies to all current and future accounts.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.