SAP-C02 Continuous Improvement for Existing Solutions Practice Question
Which TWO actions would improve the security of an S3 bucket that contains sensitive data? (Choose two.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable default encryption (SSE-S3).
Option B is correct because enabling default encryption with SSE-S3 ensures that all objects written to the bucket are automatically encrypted at rest using AES-256, protecting sensitive data even if the underlying storage media is compromised. Option C is correct because S3 Block Public Access overrides any bucket or object ACLs and bucket policies that would otherwise grant public access, preventing accidental exposure of sensitive data. Option A is not correct because Server Access Logging only records requests for auditing purposes; it does not itself restrict access or encrypt data. Option D is not correct because Versioning preserves multiple variants of objects, which aids recovery but does not improve confidentiality or access control. Option E is not correct because Lifecycle expiration deletes objects after a set period, which is a cost or retention control rather than a security hardening measure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable S3 Server Access Logging.
Why it's wrong here
Server access logging records requests after they occur, providing audit evidence rather than preventing unauthorised access. It is tempting because logging is a recognised security control, and would be correct where the requirement is forensic traceability or compliance evidence rather than blocking exposure.
- ✓
Enable default encryption (SSE-S3).
Why this is correct
SSE-S3 applies AES-256 encryption at rest automatically to every object written to the bucket, so sensitive data is protected even if callers omit encryption headers. This satisfies the question's security requirement without depending on client behaviour or key management overhead.
- ✓
Enable S3 Block Public Access.
Why this is correct
S3 Block Public Access overrides bucket policies and ACLs, rejecting any request that would make objects or the bucket publicly accessible. This directly prevents accidental exposure of sensitive data, the core security risk the question asks you to mitigate.
- ✗
Enable S3 Versioning.
Why it's wrong here
Versioning preserves prior object versions, aiding recovery after overwrite or deletion, but grants no access control over who may read the data. It is tempting because it is a common data-protection control, and would be correct where the risk is accidental deletion or ransomware rather than unauthorised access.
- ✗
Configure S3 Lifecycle to expire objects.
Why it's wrong here
Lifecycle expiry rules delete objects on a schedule, reducing storage cost and retention exposure, but they neither restrict access nor encrypt data. It is tempting because limiting retained data is a recognised privacy measure, and would be correct where the requirement is data-minimisation or cost control rather than access security.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
This SAP-C02 question is part of Courseiva's 984-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.