SAP-C02 S3 Versioning Practice Question
A company is using AWS Organizations with multiple organizational units (OUs). The security team needs to enforce that all newly created S3 buckets in the production OU have versioning enabled and are encrypted with AWS KMS. Which solution meets these requirements with minimal operational overhead?
⚠ Common exam trap
The trap is that candidates assume SCPs can enforce versioning at bucket creation because they are familiar with SCPs for preventive controls. However, versioning cannot be specified in the CreateBucket request; it must be enabled separately. Thus, the only viable option is AWS Config with auto-remediation (Option D), which is reactive but enforceable.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use AWS Config rules to detect noncompliant buckets and auto-remediate with Lambda.
It uses AWS Config rules to detect noncompliant S3 buckets (e.g., missing versioning or KMS encryption) and triggers an automated Lambda remediation to enable versioning and encryption. This ensures compliance with minimal manual intervention, though it does incur some operational overhead for Lambda maintenance. Option A is incorrect because SCPs cannot enforce versioning at bucket creation—versioning is enabled after creation via PutBucketVersioning, and the headers mentioned in the explanation do not exist. Option B only alerts and does not enforce. Option C is not scalable for OU-level enforcement and can be bypassed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Apply a service control policy (SCP) at the production OU level that denies s3:CreateBucket unless versioning and KMS encryption are specified in the request.
Why it's wrong here
Incorrect. SCPs cannot enforce versioning during bucket creation because the versioning configuration is set after bucket creation using PutBucketVersioning. The headers mentioned in the explanation do not exist. SCPs can deny actions but cannot require specific API parameters that do not exist.
- ✗
Use AWS CloudTrail to monitor bucket creation and send alerts to the security team.
Why it's wrong here
Incorrect. CloudTrail alerts only notify after the fact; they do not prevent noncompliant buckets or enforce compliance automatically.
- ✗
Create an IAM policy that requires versioning and KMS encryption when creating buckets, and attach it to all users.
Why it's wrong here
Incorrect. IAM policies attached to users are not enforceable at the OU level and can be bypassed by users with sufficient permissions (e.g., admin). Additionally, versioning cannot be enforced at creation time via IAM conditions.
- ✓
Use AWS Config rules to detect noncompliant buckets and auto-remediate with Lambda.
Why this is correct
Correct. AWS Config evaluates bucket configurations and uses custom Lambda functions to auto-remediate, enabling versioning and KMS encryption for any noncompliant bucket. This provides automated enforcement with acceptable operational overhead.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SAP-C02 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.