SCS-C02 Data Protection Practice Question
A company stores sensitive customer data in Amazon S3. To comply with data protection regulations, they need to automatically prevent any new objects from being made publicly accessible. Which S3 feature should they configure?
⚠ Common exam trap
SCS-C02 often tests the misconception that encryption (SSE-S3) or Object Lock provides access control — candidates confuse confidentiality-at-rest with public-access prevention, when only Block Public Access directly blocks public exposure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable S3 Block Public Access at the account level.
S3 Block Public Access at the account level applies a blanket deny on any policy or ACL that would make an object or bucket public, and it overrides bucket policies and ACLs. Enabling it at the account level ensures all current and future buckets in the account are protected from accidental public exposure. This is the AWS-recommended preventive control for data protection compliance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable S3 Block Public Access at the account level.
Why this is correct
Account-level S3 Block Public Access is a set of controls (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, and RestrictPublicBuckets) that act as a centralized guardrail across every bucket in the AWS account. When enabled, it overrides any bucket policy, owner policy, or object ACL that would grant public access, and it blocks both existing public grants and future attempts to make objects or buckets public. This is the most comprehensive control because it applies even if a developer mistakenly attaches a permissive bucket policy or uploads an object with a public-read ACL.
- ✗
Configure a bucket policy that denies s3:PutObject with a condition for public access.
Why it's wrong here
A bucket policy deny condition on s3:PutObject only constrains one specific write operation; it does nothing to prevent existing objects that are already public or to stop public access granted via other APIs such as PutObjectAcl. In S3, object ACLs are evaluated independently of bucket policies, so an individual object can still be made public through its ACL even when this deny statement exists. Most importantly, it does not block a separate bucket policy that grants s3:GetObject to the public, so it leaves a material gap in access control.
- ✗
Use S3 default encryption with SSE-S3.
Why it's wrong here
SSE-S3 (Amazon S3-managed keys) encrypts object data at rest, ensuring that stored bytes are unreadable without the key. However, encryption is purely a data-at-rest protection and does not participate in authorization decisions; if a bucket policy or ACL permits public read access, an unauthenticated user can still download the encrypted object and, because S3 returns the decrypted plaintext to any authorized requester, the data is effectively exposed. Enabling default encryption without applying Block Public Access leaves the bucket fully vulnerable to public exposure.
- ✗
Enable S3 Object Lock in governance mode.
Why it's wrong here
S3 Object Lock in governance mode places a retention setting that prevents users from deleting or overwriting an object version until the retention period expires, unless they have the s3:BypassGovernanceRetention permission. Its purpose is data integrity and regulatory compliance, not access control; it has no ability to block read access, so objects remain readable by any principal granted s3:GetObject. Public access can therefore coexist with an Object Lock, exposing sensitive data while the lock only prevents its removal.
Visual reference
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.