Courseiva
Security and Compliance →hardMultiple Select

DOP-C02 Security and Compliance Practice Question

A DevOps team needs to enforce that all S3 buckets in an AWS account are encrypted at rest. Which THREE steps should be taken to achieve this? (Choose THREE.)

⚠ Common exam trap

The trap is selecting tangential S3 features (access logging, Transfer Acceleration) that sound security- or performance-related but do not enforce or detect encryption at rest.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure AWS Config rules to detect buckets without encryption

Option A is correct because AWS Config managed rules such as s3-bucket-server-side-encryption-enabled continuously evaluate buckets and flag any that lack default encryption, giving the team the detection and compliance visibility needed to enforce encryption at rest. Option B is correct because an S3 bucket policy with a Deny effect on s3:PutObject when the request lacks the s3:x-amz-server-side-encryption condition (or aws:SecureTransport-style encryption conditions) blocks unencrypted uploads, actively enforcing encryption for objects written to the bucket. Option D is correct because enabling default encryption (SSE-S3/AES-256 or SSE-KMS) on each bucket ensures all objects are encrypted at rest automatically, even if clients do not specify encryption headers. Option C is not correct because S3 server access logging only records request details for auditing; it does not detect or enforce encryption. Option E is not correct because S3 Transfer Acceleration only speeds up uploads over long distances using edge locations and has no bearing on encryption at rest.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Configure AWS Config rules to detect buckets without encryption

    Why this is correct

    AWS Config's managed rule s3-bucket-server-side-encryption-enabled detects buckets where default encryption is disabled and continuously evaluates the account's infrastructure. When a noncompliant bucket is found, Config can trigger a remediation action, such as an AutoRemediate SSM document that enables default encryption, turning detection into corrective enforcement. This is a control-plane enforcement of encryption at the bucket level, rather than preventing unencrypted object writes.

  • ✓

    Use an S3 bucket policy to deny PutObject requests that do not include encryption headers

    Why this is correct

    A bucket policy can deny s3:PutObject when request lacks encryption headers by using a Deny effect with a condition like StringNotEquals on s3:x-amz-server-side-encryption for AES256 or aws:kms. This forces every object upload to explicitly declare SSE-S3 or SSE-KMS, and if a client omits the header, S3 rejects the request with an Access Denied error. It enforces encryption on each write operation at the data plane, but does not encrypt objects that are already stored.

  • ✗

    Enable S3 server access logging

    Why it's wrong here

    S3 server access logging records all requests made against a bucket and includes fields such as encryption status, requester, and object key, but it is purely an audit function. Enabling logging gives you a log file for forensic analysis or compliance reporting; it does not prevent the upload of unencrypted objects or alter default encryption settings. For enforcement, you need a bucket policy, default encryption, or an AWS Config rule, not logs.

  • ✓

    Enable default encryption on each S3 bucket

    Why this is correct

    Enabling S3 default encryption (SSE-S3 or SSE-KMS) ensures that any new object stored without an explicit encryption header is automatically encrypted at rest by S3. While this protects data at rest, it only applies at the time the object is written, so pre-existing unencrypted objects remain unencrypted unless you rewrite them or use S3 Batch Operations. It also does not require client applications to send encryption headers; a bucket policy is needed if you want to enforce explicit encryption on incoming PUTs.

  • ✗

    Enable S3 Transfer Acceleration

    Why it's wrong here

    S3 Transfer Acceleration uses globally distributed edge locations and Amazon's highly available network backbone to speed up uploads over long distances by routing traffic from edge to destination bucket. It optimizes throughput and reduces latency for large files across continents, but has no effect on how objects are encrypted during transit or at rest. Transfer Acceleration does not add SSE, TLS enforcement, or any data protection control; it is purely a performance feature.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.