SCS-C02 Data Protection Practice Question
A company is using Amazon S3 to store confidential documents. They want to ensure that all data is encrypted in transit between the S3 bucket and their on-premises application. Which of the following should be enforced?
⚠ Common exam trap
SCS-C02 often tests whether candidates conflate encryption at rest (SSE-S3) with encryption in transit, or assume a VPC endpoint enforces TLS — only the `aws:SecureTransport` bucket policy condition actually does.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add a bucket policy that denies access unless 'aws:SecureTransport' is true.
A bucket policy that denies requests unless `aws:SecureTransport` is true enforces TLS for all access to the bucket, including from on-premises applications. This is the canonical AWS pattern for requiring encryption in transit to S3. The other options either do not enforce TLS or address different concerns (encryption at rest, network path).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Add a bucket policy that denies access unless 'aws:SecureTransport' is true.
Why this is correct
The aws:SecureTransport condition key evaluates the request's protocol, so denying when it is false blocks any plain HTTP request to the bucket. This enforces TLS for data in transit between the on-premises application and S3.
- ✗
Use Amazon CloudFront with a custom origin pointing to the S3 bucket.
Why it's wrong here
CloudFront terminates TLS at edge locations and can enforce HTTPS viewer-to-edge, but the origin-facing leg to S3 is separate and the on-premises application is not a viewer. It is tempting because CloudFront offers HTTPS enforcement and caching, yet it does not govern the direct on-premises-to-S3 connection.
- ✗
Use a VPC endpoint for S3.
Why it's wrong here
A VPC endpoint carries traffic between a VPC and S3 over the AWS private network, so it never touches the public internet path from on-premises. It is tempting because gateway endpoints remove NAT costs and secure EC2-to-S3 flows, but the on-premises leg still needs TLS via an HTTPS endpoint policy.
- ✗
Enable default encryption (SSE-S3) on the bucket.
Why it's wrong here
Default encryption with SSE-S3 protects objects at rest inside the bucket; it does not encrypt the wire protocol between on-premises clients and S3. It is tempting because it is a one-click bucket setting that satisfies many compliance baselines, but enforcing TLS requires a bucket policy denying requests where aws:SecureTransport is false.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.