Courseiva
Data Protection →easyMultiple Choice

SCS-C02 Data Protection Practice Question

A company stores sensitive customer data in Amazon S3. They want to ensure that all objects are encrypted at rest using server-side encryption with AWS KMS. Which S3 bucket policy statement should be added to deny uploads that do not request SSE-KMS?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deny PutObject unless 's3:x-amz-server-side-encryption' is 'aws:kms'

The condition 's3:x-amz-server-side-encryption' with value 'aws:kms' enforces that objects are uploaded with SSE-KMS. Option A is incorrect because 'AES256' enforces SSE-S3, not SSE-KMS. Option C is incorrect because 'aws:SourceArn' is used for cross-account access, not encryption enforcement. Option D is incorrect because requiring the specific KMS key ID is too restrictive; the policy should only require the encryption type, not a particular key.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Deny PutObject unless 's3:x-amz-server-side-encryption' is 'AES256'

    Why it's wrong here

    This condition enforces SSE-S3 by requiring the request header s3:x-amz-server-side-encryption to equal AES256. AES256 is the value for S3-managed encryption keys (SSE-S3), not AWS KMS. Because the requirement is to enforce KMS-based encryption, this policy would actually reject objects encrypted with SSE-KMS and admit only SSE-S3, making it the opposite of the intended control.

  • ✓

    Deny PutObject unless 's3:x-amz-server-side-encryption' is 'aws:kms'

    Why this is correct

    This is the correct condition because it explicitly requires the s3:x-amz-server-side-encryption header to carry the value aws:kms. In a bucket policy, a Deny with this condition rejects any PutObject call that is not using SSE-KMS, thereby enforcing KMS encryption on all stored objects. It targets the encryption mode directly and avoids the ambiguity of key-ID or source-based checks.

  • ✗

    Deny PutObject unless 'aws:SourceArn' equals the bucket ARN

    Why it's wrong here

    The aws:SourceArn global condition is designed to prevent the Confused Deputy problem by limiting requests to a specific AWS resource origin, such as a service or another account. It has no relationship to object encryption, so a request could satisfy this condition and still upload an unencrypted object. Thus, it does not enforce any form of server-side encryption and fails the requirement.

  • ✗

    Deny PutObject unless 's3:x-amz-server-side-encryption-aws-kms-key-id' is present

    Why it's wrong here

    Requiring s3:x-amz-server-side-encryption-aws-kms-key-id to be present would demand a specific KMS key identifier on every upload, but the condition does not verify that the object is actually encrypted with SSE-KMS. An attacker could include the header with a valid key ID while the s3:x-amz-server-side-encryption header is absent or set to AES256, potentially bypassing the intent if the service accepts it. Furthermore, the question does not stipulate a particular KMS key, so enforcing an arbitrary specific key ID is more restrictive than necessary.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.