Courseiva

DOP-C02 Resilient Cloud Solutions Practice Question

Exhibit

Refer to the exhibit.

```
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": "s3:PutObject",
      "Resource": "arn:aws:s3:::my-bucket/*",
      "Condition": {
        "StringEquals": {
          "s3:x-amz-server-side-encryption": "AES256"
        }
      }
    },
    {
      "Effect": "Deny",
      "Action": "s3:PutObject",
      "Resource": "arn:aws:s3:::my-bucket/*",
      "Condition": {
        "StringNotEquals": {
          "s3:x-amz-server-side-encryption": "AES256"
        }
      }
    }
  ]
}
```

A DevOps engineer applies this S3 bucket policy to an S3 bucket. What is the effect of this policy?

⚠ Common exam trap

A common mix-up: candidates confuse the `x-amz-server-side-encryption` header values: `AES256` is specific to SSE-S3, not SSE-C or SSE-KMS, leading to incorrect selections of A or D.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

All objects uploaded must use server-side encryption with Amazon S3 managed keys (SSE-S3).

The S3 bucket policy in question denies uploads unless the `x-amz-server-side-encryption` header is set to `AES256`, which is the value for SSE-S3 (Amazon S3 managed keys). This ensures that all objects uploaded to the bucket must be encrypted using server-side encryption with S3-managed keys (SSE-S3). Option C correctly identifies this requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    All objects uploaded must be encrypted with SSE-C.

    Why it's wrong here

    The condition uses s3:x-amz-server-side-encryption, which must equal AES256. SSE-C does not set that header; it uses s3:x-amz-server-side-encryption-customer-algorithm with a customer-provided key, so uploads encrypted with SSE-C would fail this condition and be denied. The policy therefore explicitly excludes SSE-C rather than requiring it.

  • ✗

    All uploads to the bucket are blocked.

    Why it's wrong here

    This policy contains an Allow statement for s3:PutObject that is conditioned on the s3:x-amz-server-side-encryption header being AES256. Any upload that carries that header value is permitted, so the bucket is not fully blocked. Uploads without the header or with a different encryption value are denied, but valid SSE-S3 uploads succeed, making this statement false.

  • ✓

    All objects uploaded must use server-side encryption with Amazon S3 managed keys (SSE-S3).

    Why this is correct

    The policy grants s3:PutObject only when the s3:x-amz-server-side-encryption request header is exactly AES256. In S3, that header value maps to SSE-S3, where Amazon S3 manages the encryption keys using AES-256. Consequently, any object uploaded must be encrypted with SSE-S3, and uploads using no encryption or any other encryption method are denied.

  • ✗

    All objects uploaded must be encrypted with SSE-KMS.

    Why it's wrong here

    SSE-KMS requires the s3:x-amz-server-side-encryption header to be aws:kms, not AES256. Because this policy mandates AES256, a PutObject that attempts to use aws:kms encryption will not satisfy the condition and will be denied. Thus the bucket does not require KMS keys; it requires SSE-S3.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.