Courseiva

SAP-C02 Practice Question: Design Solutions for Organizational Complexity

A company is using AWS Organizations with multiple accounts. The security team wants to enforce that all newly created Amazon S3 buckets are encrypted with AWS KMS keys managed by the security account, and that any attempts to create unencrypted buckets are denied. The company also wants to ensure that existing buckets are remediated. Which two actions should the security team take to meet these requirements? (Choose two.)

⚠ Common exam trap

The trap here is assuming that SCPs alone can remediate existing resources, when in fact SCPs only affect new API calls and do not change existing configurations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Attach a service control policy to the root of the organization that denies s3:CreateBucket unless the request includes the s3:x-amz-server-side-encryption condition key with value aws:kms and the s3:x-amz-server-side-encryption-aws-kms-key-id condition key with the security account's KMS key ARN.

The SCP with conditions on s3:x-amz-server-side-encryption and s3:x-amz-server-side-encryption-aws-kms-key-id ensures that new buckets are created with the correct encryption and key. AWS Config conformance packs with automatic remediation detect and fix existing unencrypted buckets, providing ongoing compliance. Together, these actions enforce encryption at creation and remediate existing buckets.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use AWS CloudFormation StackSets to deploy a custom resource that scans all buckets and enables encryption, and use an SCP to deny s3:CreateBucket without encryption.

    Why it's wrong here

    A custom resource in StackSets can remediate existing buckets, but it is not event-driven and would not automatically remediate new buckets unless the stack is updated. The SCP denying s3:CreateBucket without encryption can be bypassed by creating a bucket and then enabling encryption later, so it does not guarantee encryption at creation.

  • ✓

    Attach a service control policy to the root of the organization that denies s3:CreateBucket unless the request includes the s3:x-amz-server-side-encryption condition key with value aws:kms and the s3:x-amz-server-side-encryption-aws-kms-key-id condition key with the security account's KMS key ARN.

    Why this is correct

    This SCP enforces that any s3:CreateBucket request must include both the encryption header and the specific KMS key ARN from the security account. This prevents the creation of unencrypted buckets and ensures the use of the security account's KMS key, meeting the requirement for centralized key management.

  • ✓

    Use AWS Config with a conformance pack that includes the s3-bucket-server-side-encryption-enabled rule and an automatic remediation action that enables default encryption with a KMS key from the security account.

    Why this is correct

    AWS Config conformance packs can deploy managed rules across accounts. The s3-bucket-server-side-encryption-enabled rule detects unencrypted buckets, and automatic remediation can enable default encryption using a KMS key. This addresses both new and existing buckets, ensuring compliance with the encryption requirement.

  • ✗

    Attach a service control policy to the root of the organization that denies s3:CreateBucket unless the request includes the s3:x-amz-server-side-encryption header with value aws:kms.

    Why it's wrong here

    SCPs apply to IAM principals, not to the S3 service itself, and the s3:x-amz-server-side-encryption condition is evaluated on the request. However, denying s3:CreateBucket based on that header can be bypassed if the bucket is created without the header but with default encryption enabled later. Also, this does not enforce the use of a KMS key managed by the security account.

  • ✗

    Use an SCP that denies s3:PutBucketEncryption if the request does not specify a KMS key ARN from the security account, and use AWS Config to remediate existing buckets.

    Why it's wrong here

    Denying s3:PutBucketEncryption does not prevent the creation of unencrypted buckets; it only blocks changes to encryption settings. This would not enforce encryption at creation and could leave buckets unencrypted if they are created without encryption and never updated.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SAP-C02 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.