DOP-C02 Security and Compliance Practice Question
A security audit reveals that an S3 bucket contains objects that are not encrypted. The bucket is configured with default encryption using SSE-S3. What is the most likely reason that objects are unencrypted?
⚠ Common exam trap
The trap is forgetting that default encryption is not retroactive — candidates often assume enabling it encrypts all objects, including pre-existing ones, which leads them to pick policy-based or KMS-related wrong answers.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The objects were uploaded before default encryption was enabled
S3 default encryption (SSE-S3) applies only to objects uploaded after the setting is enabled; it does not retroactively encrypt existing objects. Therefore, objects that appear unencrypted were most likely uploaded before default encryption was turned on. This is a common audit finding in buckets with historical data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The objects were uploaded with server-side encryption using AWS KMS
Why it's wrong here
If the objects had been uploaded with server-side encryption using AWS KMS (SSE-KMS), they would be encrypted at rest using a customer-managed or AWS-managed KMS key. Because SSE-KMS is a valid server-side encryption method, S3 would store the object in encrypted form, making the audit's finding of unencrypted objects impossible. Moreover, default encryption on the bucket does not affect objects already encrypted via an explicit SSE-KMS request at upload time.
- ✗
The bucket policy denies SSE-S3 encryption
Why it's wrong here
A bucket policy that denies SSE-S3 encryption affects only future write requests and access decisions; it does not retroactively alter the encryption state of existing objects. The policy would prevent new objects from being uploaded with SSE-S3, but objects already stored remain in whatever state they were originally written, which could be unencrypted if no default encryption was enabled. Thus, the presence of such a policy does not explain why existing objects are unencrypted; it may actually indicate a misconfiguration that allowed unencrypted writes.
- ✓
The objects were uploaded before default encryption was enabled
Why this is correct
S3 default encryption is a bucket-level setting that applies only to objects uploaded after the setting is enabled; it has no retroactive effect on objects that already exist. If the audit found unencrypted objects, the most plausible cause is that these objects were written before the bucket's default encryption was turned on, leaving them in their original, unencrypted state. Enabling default encryption at a later time does not trigger a re-encryption of existing data unless a separate process, such as S3 Batch Operations, is explicitly run.
- ✗
The objects were uploaded with SSE-C
Why it's wrong here
Objects uploaded with SSE-C (server-side encryption with customer-provided keys) are absolutely encrypted at rest, even though the keys are supplied by the customer and not stored by AWS. Since SSE-C uses AES-256 and S3 discards the key after the operation, the object remains encrypted for all practical purposes. Therefore, if the objects had been uploaded with SSE-C, they would not be flagged as unencrypted by the security audit.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.