Courseiva
Security and Compliance →easyMultiple Choice

DOP-C02 Security and Compliance Practice Question

Network Topology
$ aws configservice get-compliance-details-by-config-ruleconfig-rule-name s3-bucket-ssl-requests-onlyRefer to the exhibit."ComplianceDetails": ["ResourceType": "AWS::S3::Bucket","ResourceId": "my-bucket","AwsRegion": "us-east-1","ComplianceType": "NON_COMPLIANT"

The AWS Config rule 's3-bucket-ssl-requests-only' returns NON_COMPLIANT for the bucket 'my-bucket'. What does this mean?

⚠ Common exam trap

DOP-C02 often tests the specific purpose of AWS Config rules, confusing SSL-requests-only with public access or encryption rules.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The bucket's policy does not deny requests that are not using SSL.

The AWS Config rule 's3-bucket-ssl-requests-only' checks whether the bucket policy denies requests that are not using SSL (i.e., HTTP). If it returns NON_COMPLIANT, it means the bucket policy does not have a statement that denies non-SSL requests, so the bucket is not enforcing SSL-only access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The bucket's policy does not deny requests that are not using SSL.

    Why this is correct

    The AWS Config rule 's3-bucket-ssl-requests-only' requires a bucket policy that explicitly denies requests when aws:SecureTransport is false. If the policy lacks such a deny statement, the rule evaluates as NON_COMPLIANT, which is reported as 'no' in Config. Merely allowing HTTPS is insufficient; the rule demands a positive deny of HTTP to make the intent explicit and enforceable.

  • ✗

    The bucket is publicly accessible.

    Why it's wrong here

    Public accessibility refers to whether anonymous principals can read or write objects, and is independently evaluated by rules such as 's3-bucket-public-read-prohibited'. A bucket can be both publicly accessible and still have a valid deny on non-SSL requests, or it can be private yet allow HTTP. The SSL rule inspects only the transport-layer condition in the bucket policy, not who can access the bucket, so public access does not cause this rule to fail.

  • ✗

    The bucket does not have server access logging enabled.

    Why it's wrong here

    Server access logging records object-level requests to a destination bucket, which is a governance and audit feature unrelated to transport encryption. The 'ssl-requests-only' rule never examines the logging status; it evaluates the bucket policy's Condition elements for aws:SecureTransport. Whether logging is enabled or disabled has zero impact on the rule's compliance result, so this would not produce a 'no'.

  • ✗

    The bucket does not have default encryption enabled.

    Why it's wrong here

    Default encryption (SSE-S3, SSE-KMS, or SSE-C) encrypts objects at rest within S3, protecting data stored on disk. The SSL rule enforces encryption in transit by denying HTTP requests, which is a completely separate security control. A bucket can have default encryption enabled and still accept HTTP requests if the policy does not deny aws:SecureTransport=false; therefore, encryption settings do not satisfy the rule's requirement.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.