SCS-C02 Data Protection Practice Question
A company is using AWS KMS to encrypt data in Amazon S3. The security team discovers that an S3 bucket has a bucket policy that allows s3:PutObject without requiring encryption. What is the risk?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data can be uploaded without encryption at rest
When the bucket policy allows s3:PutObject without requiring encryption (e.g., x-amz-server-side-encryption header), data can be uploaded as plaintext and stored without encryption at rest, violating data protection requirements. Option A is incorrect because the KMS key usage is controlled by KMS policies, not the bucket policy. Option B is incorrect because authentication is required for PutObject, but encryption is not enforced. Option C is incorrect because encryption in transit (TLS) is separate from encryption at rest.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The KMS key can be used by unauthorized users
Why it's wrong here
An S3 bucket policy cannot grant or revoke permissions to use a KMS key; KMS access is controlled by the key policy and separate IAM actions such as kms:Decrypt and kms:GenerateDataKey. Even if the bucket policy references a KMS key, an unauthorized user could only use that key if the key's policy grants them KMS permissions. The flaw here is not unauthorized KMS usage, but the lack of an encryption requirement at the object upload level.
- ✗
Data can be downloaded without authentication
Why it's wrong here
S3 authentication is independent of encryption settings. Unless the bucket or objects are explicitly public, every GetObject request must be authenticated with IAM credentials, a presigned URL, or bucket policy permissions. Failing to require encryption at rest does not remove authentication or authorization controls, so objects cannot be downloaded anonymously solely because of this policy.
- ✗
Data in transit is not encrypted
Why it's wrong here
The bucket policy in question only governs how objects are stored at rest, not how they travel over the network. S3 data in transit is protected by TLS/HTTPS when clients use the secure endpoint, regardless of whether SSE-KMS is configured. KMS encryption applies to the object's plaintext at rest, and it has no bearing on transport-layer encryption.
- ✓
Data can be uploaded without encryption at rest
Why this is correct
If the policy permits PutObject without requiring the s3:x-amz-server-side-encryption header or a condition that forces encryption, clients can upload objects in plaintext to S3. Although the company uses KMS for encryption, that KMS key is only used when the upload explicitly requests SSE-KMS or the bucket has default encryption and the client doesn't override it. Without an explicit Deny for unencrypted uploads, some objects may remain unencrypted at rest, defeating the company's stated security intent.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.