Courseiva
Data Protection →mediumMultiple Choice

SCS-C02 Data Protection Practice Question

A company stores sensitive customer data in Amazon S3. To comply with data protection regulations, they need to automatically prevent any new objects from being made publicly accessible. Which S3 feature should they configure?

⚠ Common exam trap

SCS-C02 often tests the misconception that encryption (SSE-S3) or Object Lock provides access control — candidates confuse confidentiality-at-rest with public-access prevention, when only Block Public Access directly blocks public exposure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable S3 Block Public Access at the account level.

S3 Block Public Access at the account level applies a blanket deny on any policy or ACL that would make an object or bucket public, and it overrides bucket policies and ACLs. Enabling it at the account level ensures all current and future buckets in the account are protected from accidental public exposure. This is the AWS-recommended preventive control for data protection compliance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable S3 Block Public Access at the account level.

    Why this is correct

    Account-level S3 Block Public Access is a set of controls (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, and RestrictPublicBuckets) that act as a centralized guardrail across every bucket in the AWS account. When enabled, it overrides any bucket policy, owner policy, or object ACL that would grant public access, and it blocks both existing public grants and future attempts to make objects or buckets public. This is the most comprehensive control because it applies even if a developer mistakenly attaches a permissive bucket policy or uploads an object with a public-read ACL.

  • ✗

    Configure a bucket policy that denies s3:PutObject with a condition for public access.

    Why it's wrong here

    A bucket policy deny condition on s3:PutObject only constrains one specific write operation; it does nothing to prevent existing objects that are already public or to stop public access granted via other APIs such as PutObjectAcl. In S3, object ACLs are evaluated independently of bucket policies, so an individual object can still be made public through its ACL even when this deny statement exists. Most importantly, it does not block a separate bucket policy that grants s3:GetObject to the public, so it leaves a material gap in access control.

  • ✗

    Use S3 default encryption with SSE-S3.

    Why it's wrong here

    SSE-S3 (Amazon S3-managed keys) encrypts object data at rest, ensuring that stored bytes are unreadable without the key. However, encryption is purely a data-at-rest protection and does not participate in authorization decisions; if a bucket policy or ACL permits public read access, an unauthenticated user can still download the encrypted object and, because S3 returns the decrypted plaintext to any authorized requester, the data is effectively exposed. Enabling default encryption without applying Block Public Access leaves the bucket fully vulnerable to public exposure.

  • ✗

    Enable S3 Object Lock in governance mode.

    Why it's wrong here

    S3 Object Lock in governance mode places a retention setting that prevents users from deleting or overwriting an object version until the retention period expires, unless they have the s3:BypassGovernanceRetention permission. Its purpose is data integrity and regulatory compliance, not access control; it has no ability to block read access, so objects remain readable by any principal granted s3:GetObject. Public access can therefore coexist with an Object Lock, exposing sensitive data while the lock only prevents its removal.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.