Question 1,465 of 1,621
ANS-C01 Network Security, Compliance and Governance Practice Question
A company uses AWS Organizations to manage multiple accounts. The security team wants to ensure that all Amazon S3 buckets in the organization are encrypted at rest. Which policy should be attached to the root organizational unit to enforce this requirement?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Attach a service control policy (SCP) that denies s3:CreateBucket unless the bucket has default encryption enabled.
A service control policy (SCP) attached to the root OU can deny the s3:CreateBucket action unless the bucket is configured with default encryption, thereby enforcing encryption at rest across all accounts in the organization. Option D is correct. Option A is incorrect because AWS Config rules can detect non-compliance but cannot enforce policies in real time; they are detective, not preventive. Option B is incorrect because IAM roles are account-specific and cannot enforce encryption across all accounts centrally. Option C is incorrect because S3 bucket policies apply only to individual buckets and cannot be applied to future buckets or across accounts without manual configuration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure AWS Config rules to mark non-compliant buckets and trigger a Lambda function to add encryption.
Why it's wrong here
This is reactive, not proactive enforcement.
- ✗
Create an IAM role in each account that requires encryption for any S3 operation.
Why it's wrong here
IAM roles are not inherited across accounts and cannot enforce across all accounts centrally.
- ✗
Use an S3 bucket policy on every existing and future bucket to deny unencrypted uploads.
Why it's wrong here
Bucket policies are per-bucket and cannot be enforced automatically on new buckets.
- ✓
Attach a service control policy (SCP) that denies s3:CreateBucket unless the bucket has default encryption enabled.
Why this is correct
SCPs can enforce encryption at the organizational level.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
About these practice questions
Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →
Last reviewed: Jun 20, 2026
This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.
Question Discussion
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
Sign in to join the discussion.