SCS-C02 Data Protection Practice Question
A company stores sensitive data in Amazon S3 and requires that objects are automatically encrypted using server-side encryption with AWS KMS. The bucket policy must deny any PUT request that does not include the x-amz-server-side-encryption header with value aws:kms. Which bucket policy condition key should be used?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
s3:x-amz-server-side-encryption
The condition key s3:x-amz-server-side-encryption can be used to check the header value. Condition key aws:SourceIp is for source IP; aws:RequestedRegion is for region; kms:EncryptionContext is for KMS encryption context. Option A is correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
s3:x-amz-server-side-encryption
Why this is correct
The s3:x-amz-server-side-encryption condition key is the correct way to enforce encryption in an S3 bucket policy, as it directly evaluates the x-amz-server-side-encryption header that clients must include in PutObject requests. You can combine it with StringEquals to require a specific value such as aws:kms or AES256, and use a Deny effect to reject any upload lacking the required encryption header. This condition key is evaluated by S3 during the request, making it a precise, application-level control that cannot be bypassed by network or regional context.
- ✗
aws:SourceIp
Why it's wrong here
The aws:SourceIp condition key is wrong because it restricts access based on the requester's IP address, not on the presence or value of an encryption header. While it is a useful global condition for network-level access control, such as allowing only traffic from a corporate VPN, it does not inspect HTTP headers like x-amz-server-side-encryption. An attacker with a permitted IP address could still upload unencrypted objects, so this key does not satisfy the requirement to enforce encryption at the bucket policy level.
- ✗
aws:RequestedRegion
Why it's wrong here
The aws:RequestedRegion condition key is wrong because it evaluates the AWS region to which the request is directed, not the encryption header. This key is typically used to restrict operations to specific regions—for example, to enforce data residency by denying requests that target a non-compliant region endpoint. It has no ability to read or validate the x-amz-server-side-encryption header on an S3 PUT request, so it cannot enforce encryption requirements regardless of how it is configured.
- ✗
kms:EncryptionContext
Why it's wrong here
The kms:EncryptionContext condition key is wrong because it is designed for use in KMS key policies and grants, not S3 bucket policies. It refers to the encryption context—a set of key-value pairs—that a caller passes to AWS KMS when using server-side encryption with KMS (SSE-KMS), and it is evaluated by the KMS service during cryptographic operations. S3 bucket policies do not support this condition key; S3 itself evaluates s3:x-amz-server-side-encryption, not the KMS encryption context, so this option cannot be used to enforce encryption in a bucket policy.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.