SCS-C02 Data Protection Practice Question
A company stores sensitive customer data in Amazon S3. They want to ensure that all objects are encrypted at rest using server-side encryption with AWS KMS. Which S3 bucket policy statement should be added to deny uploads that do not request SSE-KMS?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deny PutObject unless 's3:x-amz-server-side-encryption' is 'aws:kms'
The condition 's3:x-amz-server-side-encryption' with value 'aws:kms' enforces that objects are uploaded with SSE-KMS. Option A is incorrect because 'AES256' enforces SSE-S3, not SSE-KMS. Option C is incorrect because 'aws:SourceArn' is used for cross-account access, not encryption enforcement. Option D is incorrect because requiring the specific KMS key ID is too restrictive; the policy should only require the encryption type, not a particular key.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deny PutObject unless 's3:x-amz-server-side-encryption' is 'AES256'
Why it's wrong here
This condition enforces SSE-S3 by requiring the request header s3:x-amz-server-side-encryption to equal AES256. AES256 is the value for S3-managed encryption keys (SSE-S3), not AWS KMS. Because the requirement is to enforce KMS-based encryption, this policy would actually reject objects encrypted with SSE-KMS and admit only SSE-S3, making it the opposite of the intended control.
- ✓
Deny PutObject unless 's3:x-amz-server-side-encryption' is 'aws:kms'
Why this is correct
This is the correct condition because it explicitly requires the s3:x-amz-server-side-encryption header to carry the value aws:kms. In a bucket policy, a Deny with this condition rejects any PutObject call that is not using SSE-KMS, thereby enforcing KMS encryption on all stored objects. It targets the encryption mode directly and avoids the ambiguity of key-ID or source-based checks.
- ✗
Deny PutObject unless 'aws:SourceArn' equals the bucket ARN
Why it's wrong here
The aws:SourceArn global condition is designed to prevent the Confused Deputy problem by limiting requests to a specific AWS resource origin, such as a service or another account. It has no relationship to object encryption, so a request could satisfy this condition and still upload an unencrypted object. Thus, it does not enforce any form of server-side encryption and fails the requirement.
- ✗
Deny PutObject unless 's3:x-amz-server-side-encryption-aws-kms-key-id' is present
Why it's wrong here
Requiring s3:x-amz-server-side-encryption-aws-kms-key-id to be present would demand a specific KMS key identifier on every upload, but the condition does not verify that the object is actually encrypted with SSE-KMS. An attacker could include the header with a valid key ID while the s3:x-amz-server-side-encryption header is absent or set to AES256, potentially bypassing the intent if the service accepts it. Furthermore, the question does not stipulate a particular KMS key, so enforcing an arbitrary specific key ID is more restrictive than necessary.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.