DOP-C02 Security and Compliance Practice Question
An organization wants to enforce that all Amazon S3 buckets are encrypted with SSE-S3. Which AWS service can be used to automatically remediate non-compliant buckets?
⚠ Common exam trap
The trap is assuming that IAM policies or CloudTrail can enforce encryption, when only AWS Config provides the evaluation and auto-remediation capability for resource compliance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Config rules with auto-remediation
AWS Config rules can evaluate whether S3 buckets have SSE-S3 encryption enabled and trigger automatic remediation actions via SSM Automation documents. This provides continuous compliance monitoring and enforcement without manual intervention, directly addressing the requirement to automatically remediate non-compliant buckets.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS CloudTrail
Why it's wrong here
AWS CloudTrail is a governance, risk, and compliance service that records API activity in your account, including S3 bucket operations, but it is purely an auditing and logging tool. It does not evaluate current resource configuration against a desired policy, nor can it trigger changes to an existing bucket's encryption settings. CloudTrail logs can show that a bucket was created without SSE-S3, but they cannot enforce or remediate that non-compliance, so it fails to 'ensure all buckets have encryption'.
- ✓
AWS Config rules with auto-remediation
Why this is correct
AWS Config rules with auto-remediation are the correct choice because they provide continuous monitoring and automated correction. A managed rule like s3-bucket-server-side-encryption-enabled detects non-compliant buckets, and the associated remediation action (via SSM Automation or a custom Lambda) automatically applies SSE-S3 default encryption to the bucket. This is the only option that both detects existing non-compliant buckets and actively modifies their configuration to become compliant, satisfying the organization's requirement in real time.
- ✗
IAM policies
Why it's wrong here
IAM policies are a preventive control: you could write a policy that denies s3:PutBucketEncryption or requires encryption headers on s3:PutObject, which prevents future non-encrypted bucket creations or object uploads. However, IAM policies do not evaluate or alter the configuration of buckets that already exist and are non-compliant. They cannot remediate a bucket created before the policy took effect, because IAM only controls permission to perform actions—it never changes a resource's attributes directly.
- ✗
AWS Service Catalog
Why it's wrong here
AWS Service Catalog enables organizations to govern the creation of new S3 buckets by offering approved templates (CloudFormation products) that include encryption settings. It has no mechanism to scan or remediate resources that already exist outside its control; buckets created directly via the S3 API or console without encryption would remain non-compliant. Service Catalog is a preventive provisioning tool, not a detective or corrective control, so it cannot enforce encryption on the organization's existing bucket fleet.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on DOP-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A security team wants to enforce that all Amazon S3 buckets in the organization are encrypted at rest. Which actions can achieve this? (Select THREE.)
hard- A.Enable S3 Block Public Access at the account level
- B.Set up Cross-Region Replication for all buckets
- ✓ C.Configure an AWS Config rule to detect unencrypted buckets and trigger remediation
- ✓ D.Apply a bucket policy that denies PutObject requests without the x-amz-server-side-encryption header
- ✓ E.Use an SCP to require encryption on all S3 buckets
Why C: Option C is correct because an AWS Config managed rule such as s3-bucket-server-side-encryption-enabled continuously evaluates buckets and can invoke an SSM Automation remediation to enable default encryption on non-compliant buckets. Option D is correct because a bucket policy with a Deny effect on s3:PutObject when the s3:x-amz-server-side-encryption condition key is absent (or does not equal AES256/aws:kms) blocks unencrypted uploads at the API level. Option E is correct because a Service Control Policy attached at the OU or account level can deny s3:CreateBucket or s3:PutBucketEncryption actions that do not enforce encryption, giving organization-wide preventive control. Option A is not correct because S3 Block Public Access only restricts public access via ACLs and policies; it has no bearing on encryption at rest. Option B is not correct because Cross-Region Replication copies objects to another bucket and does not enforce or enable encryption on the source buckets.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.