Courseiva
Design for New Solutions →mediumMultiple Select

SAP-C02 Design for New Solutions Practice Question

A company is designing a data lake on Amazon S3. Data is ingested from multiple sources and stored as Parquet files partitioned by date. The company needs to ensure that only authorized users can access the data, and that the data is encrypted at rest. Which TWO actions should the company take to meet these requirements? (Choose TWO.)

⚠ Common exam trap

The trap is selecting client-side encryption or ACLs as primary controls when the question asks for centralized encryption and role-based access — SSE-KMS and bucket policies are the AWS-recommended best practices.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable default encryption with SSE-KMS on the S3 bucket.

Option A is correct because enabling default encryption with SSE-KMS on the S3 bucket ensures all objects are encrypted at rest using AWS KMS-managed keys, satisfying the encryption requirement without relying on each uploader to set encryption headers. Option E is correct because an S3 bucket policy that allows access only from specific IAM roles enforces least-privilege authorization, ensuring that only the intended IAM principals can read or write the Parquet data. Option B is not required because server-side encryption with SSE-KMS already meets the encryption-at-rest requirement, and client-side encryption adds key-management complexity without being mandated. Option C is incorrect because S3 server access logging only records request activity for auditing; it does not control access or encrypt data. Option D is incorrect because bucket ACLs are legacy, coarse-grained access mechanisms and cannot express the fine-grained, role-based authorization that a bucket policy provides.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable default encryption with SSE-KMS on the S3 bucket.

    Why this is correct

    SSE-KMS default encryption ensures every object written to the bucket is encrypted at rest using AWS KMS keys, satisfying the encryption requirement. It also enables granular key policies and audit trails via CloudTrail, supporting control over who can decrypt the data lake contents.

  • ✗

    Use client-side encryption before uploading to S3.

    Why it's wrong here

    Client-side encryption protects data before upload but places key management entirely on the company, and it does nothing to enforce which users may access objects. It is tempting because it satisfies encryption at rest, yet SSE-KMS with bucket policies and IAM handles both authorisation and encryption natively.

  • ✗

    Enable S3 server access logging.

    Why it's wrong here

    Server access logging records requests made to the bucket for auditing purposes; it neither restricts access to authorised users nor encrypts stored objects. It is tempting because logging sounds security-related, but the requirement is authorisation and encryption at rest, which logging cannot deliver.

  • ✗

    Use a bucket ACL to grant access to the data lake.

    Why it's wrong here

    Bucket ACLs grant coarse read/write permissions to predefined grantee groups and cannot express the fine-grained, identity-based authorisation the scenario needs. They are tempting as a legacy S3 access mechanism, but IAM policies with bucket policies provide the required least-privilege control.

  • ✓

    Configure an S3 bucket policy that allows access only from specific IAM roles.

    Why this is correct

    An S3 bucket policy restricting access to specific IAM roles enforces least-privilege authorisation at the bucket level, ensuring only approved identities can read or write the Parquet data. This directly satisfies the requirement that only authorised users access the data lake.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SAP-C02 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.