SAP-C02 Continuous Improvement for Existing Solutions Practice Question
A company is using Amazon S3 to store sensitive data. The security team wants to ensure that all objects uploaded to specific S3 buckets are encrypted at rest. Which TWO actions should they take? (Choose 2)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a bucket policy that denies PutObject without the x-amz-server-side-encryption header.
Option A is correct because a bucket policy with a Deny effect on s3:PutObject conditioned on the absence of the s3:x-amz-server-side-encryption header (or Null condition on that key) forces every uploader to explicitly request server-side encryption, preventing unencrypted PUT requests. Option B is correct because configuring default bucket encryption with SSE-S3 (AES-256) or SSE-KMS automatically encrypts objects at rest even when the request does not include an encryption header, providing a baseline guarantee for all uploaded data. Option C is not relevant because Cross-Region Replication only copies objects to another bucket and does not enforce encryption at rest on the source bucket. Option D is not relevant because Versioning preserves multiple object versions but does not itself encrypt data. Option E is not relevant because Server Access Logs record request activity for auditing, not encryption enforcement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use a bucket policy that denies PutObject without the x-amz-server-side-encryption header.
Why this is correct
A bucket policy denying PutObject requests that lack the x-amz-server-side-encryption header enforces encryption at upload time, satisfying the requirement that all objects in the specified buckets be encrypted at rest. This blocks unencrypted PUTs before any object is written, rather than merely detecting them afterwards.
- ✓
Configure default encryption on the S3 buckets to use SSE-S3 or SSE-KMS.
Why this is correct
Default encryption applies SSE-S3 or SSE-KMS automatically to every object written to the bucket, including uploads that omit encryption headers. This guarantees encryption at rest without relying on each client to request it, satisfying the stated requirement.
- ✗
Enable S3 Cross-Region Replication.
Why it's wrong here
Cross-Region Replication copies objects to another bucket; it does not enforce encryption at rest on the source bucket. It suits durability and latency requirements. The stem needs bucket policies or default encryption settings that reject or encrypt unencrypted uploads.
- ✗
Enable S3 Versioning on the buckets.
Why it's wrong here
Versioning preserves multiple object versions for recovery; it does not encrypt data at rest. It is tempting because versioning protects against accidental deletion and overwrites, so it would be the right choice for durability or ransomware recovery, but it leaves objects unencrypted, failing the stated encryption requirement.
- ✗
Enable S3 Server Access Logs.
Why it's wrong here
Server access logs record requests made to the bucket for auditing; they do not encrypt stored objects. Logging is tempting because it supports security monitoring and forensic investigation, making it correct for tracking access patterns, but it leaves object data unencrypted at rest, so it cannot satisfy the encryption mandate.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
This SAP-C02 question is part of Courseiva's 984-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.