A company is using AWS CloudFormation to deploy infrastructure. The security team requires that all Amazon S3 buckets created by CloudFormation must be encrypted at rest. What should a solutions architect do to enforce this requirement?
Trap 1: Enable default encryption on each bucket using SSE-S3.
Default encryption only applies to objects uploaded without encryption headers; it can be overridden.
Trap 2: Require that all buckets use AWS KMS managed keys for encryption.
This does not enforce encryption at upload time.
Trap 3: Use a CloudFormation stack policy to prevent modification of bucket…
Stack policies protect resources from updates, not from unencrypted uploads.
- A
Enable default encryption on each bucket using SSE-S3.
Why it fails: Default encryption only applies to objects uploaded without encryption headers; it can be overridden.
- B
Add an S3 bucket policy that denies s3:PutObject without the x-amz-server-side-encryption header.
A bucket policy denying s3:PutObject requests lacking the x-amz-server-side-encryption header enforces encryption at rest for every object written, regardless of how the bucket was created. This satisfies the security team's requirement across all CloudFormation-created buckets without modifying templates, though it governs object uploads rather than default bucket encryption settings.
- C
Require that all buckets use AWS KMS managed keys for encryption.
Why it fails: This does not enforce encryption at upload time.
- D
Use a CloudFormation stack policy to prevent modification of bucket encryption settings.
Why it fails: Stack policies protect resources from updates, not from unencrypted uploads.