DOP-C02 Security and Compliance Practice Question
Network Topology
The AWS Config rule 's3-bucket-ssl-requests-only' returns NON_COMPLIANT for the bucket 'my-bucket'. What does this mean?
⚠ Common exam trap
DOP-C02 often tests the specific purpose of AWS Config rules, confusing SSL-requests-only with public access or encryption rules.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The bucket's policy does not deny requests that are not using SSL.
The AWS Config rule 's3-bucket-ssl-requests-only' checks whether the bucket policy denies requests that are not using SSL (i.e., HTTP). If it returns NON_COMPLIANT, it means the bucket policy does not have a statement that denies non-SSL requests, so the bucket is not enforcing SSL-only access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The bucket's policy does not deny requests that are not using SSL.
Why this is correct
The AWS Config rule 's3-bucket-ssl-requests-only' requires a bucket policy that explicitly denies requests when aws:SecureTransport is false. If the policy lacks such a deny statement, the rule evaluates as NON_COMPLIANT, which is reported as 'no' in Config. Merely allowing HTTPS is insufficient; the rule demands a positive deny of HTTP to make the intent explicit and enforceable.
- ✗
The bucket is publicly accessible.
Why it's wrong here
Public accessibility refers to whether anonymous principals can read or write objects, and is independently evaluated by rules such as 's3-bucket-public-read-prohibited'. A bucket can be both publicly accessible and still have a valid deny on non-SSL requests, or it can be private yet allow HTTP. The SSL rule inspects only the transport-layer condition in the bucket policy, not who can access the bucket, so public access does not cause this rule to fail.
- ✗
The bucket does not have server access logging enabled.
Why it's wrong here
Server access logging records object-level requests to a destination bucket, which is a governance and audit feature unrelated to transport encryption. The 'ssl-requests-only' rule never examines the logging status; it evaluates the bucket policy's Condition elements for aws:SecureTransport. Whether logging is enabled or disabled has zero impact on the rule's compliance result, so this would not produce a 'no'.
- ✗
The bucket does not have default encryption enabled.
Why it's wrong here
Default encryption (SSE-S3, SSE-KMS, or SSE-C) encrypts objects at rest within S3, protecting data stored on disk. The SSL rule enforces encryption in transit by denying HTTP requests, which is a completely separate security control. A bucket can have default encryption enabled and still accept HTTP requests if the policy does not deny aws:SecureTransport=false; therefore, encryption settings do not satisfy the rule's requirement.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.