Courseiva

SAP-C02 S3 Versioning Practice Question

A company is using AWS Organizations with multiple organizational units (OUs). The security team needs to enforce that all newly created S3 buckets in the production OU have versioning enabled and are encrypted with AWS KMS. Which solution meets these requirements with minimal operational overhead?

⚠ Common exam trap

The trap is that candidates assume SCPs can enforce versioning at bucket creation because they are familiar with SCPs for preventive controls. However, versioning cannot be specified in the CreateBucket request; it must be enabled separately. Thus, the only viable option is AWS Config with auto-remediation (Option D), which is reactive but enforceable.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use AWS Config rules to detect noncompliant buckets and auto-remediate with Lambda.

It uses AWS Config rules to detect noncompliant S3 buckets (e.g., missing versioning or KMS encryption) and triggers an automated Lambda remediation to enable versioning and encryption. This ensures compliance with minimal manual intervention, though it does incur some operational overhead for Lambda maintenance. Option A is incorrect because SCPs cannot enforce versioning at bucket creation—versioning is enabled after creation via PutBucketVersioning, and the headers mentioned in the explanation do not exist. Option B only alerts and does not enforce. Option C is not scalable for OU-level enforcement and can be bypassed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Apply a service control policy (SCP) at the production OU level that denies s3:CreateBucket unless versioning and KMS encryption are specified in the request.

    Why it's wrong here

    Incorrect. SCPs cannot enforce versioning during bucket creation because the versioning configuration is set after bucket creation using PutBucketVersioning. The headers mentioned in the explanation do not exist. SCPs can deny actions but cannot require specific API parameters that do not exist.

  • ✗

    Use AWS CloudTrail to monitor bucket creation and send alerts to the security team.

    Why it's wrong here

    Incorrect. CloudTrail alerts only notify after the fact; they do not prevent noncompliant buckets or enforce compliance automatically.

  • ✗

    Create an IAM policy that requires versioning and KMS encryption when creating buckets, and attach it to all users.

    Why it's wrong here

    Incorrect. IAM policies attached to users are not enforceable at the OU level and can be bypassed by users with sufficient permissions (e.g., admin). Additionally, versioning cannot be enforced at creation time via IAM conditions.

  • ✓

    Use AWS Config rules to detect noncompliant buckets and auto-remediate with Lambda.

    Why this is correct

    Correct. AWS Config evaluates bucket configurations and uses custom Lambda functions to auto-remediate, enabling versioning and KMS encryption for any noncompliant bucket. This provides automated enforcement with acceptable operational overhead.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SAP-C02 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.