Courseiva
Design Solutions for Organizational ComplexitymediumMultiple SelectObjective-mapped

How to Enforce S3 Bucket Encryption Across All AWS Accounts

A company has 100 AWS accounts in AWS Organizations. The security team wants to enforce that all Amazon S3 buckets have encryption enabled. Which TWO actions should the team take to meet this requirement? (Choose TWO.)

Quick Answer

The correct answer is to use AWS Config rules to detect S3 buckets without default encryption and auto-remediate with a Lambda function, combined with an SCP that denies disabling S3 Block Public Access at the account level. This works because AWS Config continuously evaluates your S3 buckets against the encryption rule, and the Lambda function automatically enables default encryption on any non-compliant bucket, while the SCP prevents any account from turning off the Block Public Access setting, ensuring that all buckets remain private and encryption cannot be bypassed. On the AWS Certified Solutions Architect Professional SAP-C02 exam, this scenario tests your ability to enforce S3 bucket encryption across all AWS accounts using a detective and preventive control pair—a common pattern for organization-wide compliance. A frequent trap is choosing only one control, such as a single AWS Config rule without auto-remediation, or forgetting that SCPs can block disabling of security settings. Memory tip: think “Detect and Prevent”—Config detects, SCP prevents.

⚠ Common exam trap

A common trap is to think that S3 Block Public Access (Option C) enforces encryption, but it only blocks public access. Encryption must be explicitly required via SCPs or Config rules.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Create an SCP that denies s3:PutObject unless encryption headers are included.

An SCP can deny the s3:PutObject action unless encryption headers are included, using the condition key s3:x-amz-server-side-encryption. This enforces server-side encryption on all object uploads across the organization. Option E is correct because AWS Config rules can detect S3 buckets without default encryption and trigger an auto-remediation Lambda function to enable it, ensuring compliance. Option C is incorrect because S3 Block Public Access does not enforce encryption; it only prevents public access. Option B is incorrect because SCPs cannot 'require' encryption in the sense of enabling it; they can only deny non-compliant requests, making Option A the precise action. Option D is incorrect because denying CreateBucket does not enforce encryption on existing buckets.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Create an SCP that denies s3:PutObject unless encryption headers are included.

    Why this is correct

    Correct. An SCP can deny s3:PutObject unless encryption headers are present using the condition key s3:x-amz-server-side-encryption, enforcing encryption on uploads across all accounts.

  • Create an SCP that requires all objects to be uploaded with server-side encryption.

    Why it's wrong here

    Incorrect. While similar to A, the phrasing 'requires all objects to be uploaded with server-side encryption' is imprecise. SCPs can only deny non-compliant requests; they cannot proactively enable encryption. Option A is the accurate action.

  • Enable S3 Block Public Access at the account level and use a service control policy to prevent disabling it.

    Why it's wrong here

    Incorrect. S3 Block Public Access only prevents public access; it does not enforce encryption. This is a common misconception.

  • Create an SCP that denies the s3:CreateBucket action to all accounts.

    Why it's wrong here

    Incorrect. Denying the s3:CreateBucket action does not enforce encryption on existing buckets and would prevent all bucket creation, which is overly restrictive.

  • Use AWS Config rules to detect buckets without default encryption and auto-remediate with a Lambda function.

    Why this is correct

    Correct. AWS Config rules can detect buckets without default encryption and trigger a Lambda function to enable it, providing continuous compliance across all accounts.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SAP-C02 question from scratch — 1,660 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SAP-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A global company uses AWS Organizations with hundreds of accounts. The security team requires that all S3 buckets across the organization block public access. They want to enforce this policy without modifying existing bucket policies. Which solution should they use?

hard
  • A.Use AWS CloudTrail to monitor for public bucket creation and alert the security team.
  • B.Create a service control policy (SCP) that denies s3:PutBucketPolicy for any bucket that allows public access.
  • C.Use AWS Config rules to detect public buckets and auto-remediate with a Lambda function.
  • D.Create an SCP that denies s3:PutAccountPublicAccessBlock and s3:DeleteAccountPublicAccessBlock, and enable S3 Block Public Access at the account level via a custom resource in each account.

Why D: S3 Block Public Access settings at the account level override bucket-level policies and can be enforced organization-wide via a service control policy (SCP) that denies the ability to disable or delete those settings. By using a custom resource (e.g., AWS CloudFormation) to enable S3 Block Public Access at the account level in each account, and an SCP to prevent any account from modifying those settings, the security team ensures all buckets in the organization block public access without needing to modify existing bucket policies.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.