Courseiva
Security and Compliance →mediumMultiple Choice

DOP-C02 Security and Compliance Practice Question

A security audit reveals that an S3 bucket contains objects that are not encrypted. The bucket is configured with default encryption using SSE-S3. What is the most likely reason that objects are unencrypted?

⚠ Common exam trap

The trap is forgetting that default encryption is not retroactive — candidates often assume enabling it encrypts all objects, including pre-existing ones, which leads them to pick policy-based or KMS-related wrong answers.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The objects were uploaded before default encryption was enabled

S3 default encryption (SSE-S3) applies only to objects uploaded after the setting is enabled; it does not retroactively encrypt existing objects. Therefore, objects that appear unencrypted were most likely uploaded before default encryption was turned on. This is a common audit finding in buckets with historical data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The objects were uploaded with server-side encryption using AWS KMS

    Why it's wrong here

    If the objects had been uploaded with server-side encryption using AWS KMS (SSE-KMS), they would be encrypted at rest using a customer-managed or AWS-managed KMS key. Because SSE-KMS is a valid server-side encryption method, S3 would store the object in encrypted form, making the audit's finding of unencrypted objects impossible. Moreover, default encryption on the bucket does not affect objects already encrypted via an explicit SSE-KMS request at upload time.

  • ✗

    The bucket policy denies SSE-S3 encryption

    Why it's wrong here

    A bucket policy that denies SSE-S3 encryption affects only future write requests and access decisions; it does not retroactively alter the encryption state of existing objects. The policy would prevent new objects from being uploaded with SSE-S3, but objects already stored remain in whatever state they were originally written, which could be unencrypted if no default encryption was enabled. Thus, the presence of such a policy does not explain why existing objects are unencrypted; it may actually indicate a misconfiguration that allowed unencrypted writes.

  • ✓

    The objects were uploaded before default encryption was enabled

    Why this is correct

    S3 default encryption is a bucket-level setting that applies only to objects uploaded after the setting is enabled; it has no retroactive effect on objects that already exist. If the audit found unencrypted objects, the most plausible cause is that these objects were written before the bucket's default encryption was turned on, leaving them in their original, unencrypted state. Enabling default encryption at a later time does not trigger a re-encryption of existing data unless a separate process, such as S3 Batch Operations, is explicitly run.

  • ✗

    The objects were uploaded with SSE-C

    Why it's wrong here

    Objects uploaded with SSE-C (server-side encryption with customer-provided keys) are absolutely encrypted at rest, even though the keys are supplied by the customer and not stored by AWS. Since SSE-C uses AES-256 and S3 discards the key after the operation, the object remains encrypted for all practical purposes. Therefore, if the objects had been uploaded with SSE-C, they would not be flagged as unencrypted by the security audit.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.