DOP-C02 Security and Compliance Practice Question
A financial services company is migrating its applications to AWS. The compliance team requires that all Amazon S3 buckets containing personally identifiable information (PII) must have server-side encryption enabled and block public access. The DevOps team discovers that some S3 buckets are not compliant. Which TWO actions should the team take to enforce these requirements automatically for all current and future buckets? (Select TWO.)
⚠ Common exam trap
A common mix-up: candidates confuse detective controls (like CloudTrail alerts) with preventive or corrective controls (like AWS Config auto-remediation or SCPs), leading them to select Option A instead of the automated enforcement mechanisms that actually fix noncompliant buckets.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use AWS Config managed rules to detect noncompliant buckets and automatically remediate by applying encryption and blocking public access.
To enforce these requirements automatically for all current and future buckets, the team should use AWS Config managed rules (e.g., s3-bucket-server-side-encryption-enabled and s3-bucket-public-read-prohibited) with auto-remediation to detect and automatically fix noncompliant buckets (option B). Additionally, an SCP that denies s3:PutBucketPublicAccessBlock and s3:PutBucketEncryption actions when the required settings are not specified prevents noncompliant buckets from being created in the first place across all accounts (option E). Together, these provide preventive and corrective controls for all existing and future buckets.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable AWS CloudTrail to log all S3 API calls and send alerts when noncompliant buckets are created.
Why it's wrong here
AWS CloudTrail records all S3 API calls and can trigger alerts when noncompliant buckets are created, but it is strictly a detective control. Logging does not prevent the bucket from being created with insecure settings, nor does it automatically remediate the resource after the fact. Alerting requires you to build and maintain monitoring infrastructure, which adds complexity without enforcing the required encryption or public-access protections.
- ✓
Use AWS Config managed rules to detect noncompliant buckets and automatically remediate by applying encryption and blocking public access.
Why this is correct
AWS Config managed rules such as s3-bucket-public-read-prohibited and s3-bucket-default-encryption-enabled continuously evaluate bucket configurations against your compliance requirements. When a violation is detected, you can attach remediation actions, typically SSM Automation runbooks, to automatically apply default encryption and block public access. This combination of detection and corrective automation meets the enforcement need by actively fixing noncompliant buckets without requiring manual intervention.
- ✗
Attach an IAM permissions boundary to all users that prevents them from creating or modifying S3 buckets.
Why it's wrong here
An IAM permissions boundary that denies s3:CreateBucket and s3:PutBucketEncryption would prevent users from creating or modifying S3 buckets entirely, which is more restrictive than the requirement to enforce specific security settings. It also fails to protect against other principals such as the account root user, existing roles, or service accounts that may already have permissions. The boundary treats all bucket activity as forbidden instead of allowing creation only when the required encryption and public-access controls are present.
- ✗
Apply an S3 bucket policy to each existing bucket that denies all access unless encryption is enabled.
Why it's wrong here
Applying a bucket policy to each existing bucket that denies access unless encryption is enabled only affects buckets that exist at the time of application. Newly created buckets would not inherit this policy, and nothing stops a bucket owner from later modifying or removing the policy. It is a static, one-time control that lacks the continuous, automated enforcement needed to guarantee every current and future bucket remains encrypted and non-public.
- ✓
Create an SCP that denies the s3:PutBucketPublicAccessBlock and s3:PutBucketEncryption actions when the required settings are not specified.
Why this is correct
Service control policies (SCPs) at the AWS Organizations level can deny S3 actions like s3:PutBucketPublicAccessBlock and s3:PutBucketEncryption unless the request includes the required configuration settings. Because SCPs apply to every principal in the account, including the root user, they prevent a bucket from ever being created or modified with insecure settings in the first place. This makes the SCP a true preventive control, though it must be carefully crafted to use condition keys that inspect the API request parameters.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.