SAP-C02 Practice Question: Design Solutions for Organizational Complexity
A company has a multi-account AWS environment with over 500 accounts managed through AWS Organizations. The accounts are organized into OUs by business unit. The security team wants to enforce a policy that all S3 buckets must have server-side encryption enabled (SSE-S3 or SSE-KMS). They also want to automatically remediate any existing non-compliant buckets and prevent creation of new non-compliant buckets. Currently, there is no centralized logging or monitoring. The team has tried using AWS Config rules with auto-remediation, but they found that Config rules are not triggered for buckets created before the rule was enabled, and some teams are creating buckets via AWS CloudFormation that bypass the Config rule evaluation. The team needs a solution that covers all buckets, regardless of creation method or time. What should the team do?
⚠ Common exam trap
Candidates often assume AWS Config rules automatically evaluate all existing resources when enabled, but they only evaluate resources on configuration changes after enablement unless a manual or scheduled evaluation is triggered, leading to the misconception that Config alone cannot cover pre-existing buckets.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Apply an SCP that denies s3:CreateBucket if encryption is not specified, and use AWS Config rules with Lambda auto-remediation to fix existing non-compliant buckets.
An SCP applied at the root or OU level can deny s3:CreateBucket when encryption settings are not specified, preventing creation of non-compliant buckets regardless of the method (console, CLI, CloudFormation). For existing non-compliant buckets, AWS Config rules with Lambda auto-remediation can scan and fix them, and Config rules can be configured to evaluate all existing resources by running a manual or scheduled evaluation after the rule is enabled, addressing the gap where buckets created before the rule was enabled were not evaluated.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use AWS CloudFormation StackSets to deploy a bucket template that enforces encryption across all accounts.
Why it's wrong here
Does not cover buckets created outside CloudFormation.
- ✓
Apply an SCP that denies s3:CreateBucket if encryption is not specified, and use AWS Config rules with Lambda auto-remediation to fix existing non-compliant buckets.
Why this is correct
SCP prevents new non-compliant buckets; Config remediates existing ones.
- ✗
Use AWS CloudTrail to detect non-compliant bucket creation and send alerts to administrators.
Why it's wrong here
Alerts only, no prevention or remediation.
- ✗
Use S3 bucket policies to deny PutObject if encryption is not set.
Why it's wrong here
Does not enforce encryption on the bucket itself.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SAP-C02 question from scratch — 1,660 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.