Courseiva
Data Protection →mediumMultiple Choice

SCS-C02 Data Protection Practice Question

A company stores sensitive data in Amazon S3 and requires that objects are automatically encrypted using server-side encryption with AWS KMS. The bucket policy must deny any PUT request that does not include the x-amz-server-side-encryption header with value aws:kms. Which bucket policy condition key should be used?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

s3:x-amz-server-side-encryption

The condition key s3:x-amz-server-side-encryption can be used to check the header value. Condition key aws:SourceIp is for source IP; aws:RequestedRegion is for region; kms:EncryptionContext is for KMS encryption context. Option A is correct.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    s3:x-amz-server-side-encryption

    Why this is correct

    The s3:x-amz-server-side-encryption condition key is the correct way to enforce encryption in an S3 bucket policy, as it directly evaluates the x-amz-server-side-encryption header that clients must include in PutObject requests. You can combine it with StringEquals to require a specific value such as aws:kms or AES256, and use a Deny effect to reject any upload lacking the required encryption header. This condition key is evaluated by S3 during the request, making it a precise, application-level control that cannot be bypassed by network or regional context.

  • ✗

    aws:SourceIp

    Why it's wrong here

    The aws:SourceIp condition key is wrong because it restricts access based on the requester's IP address, not on the presence or value of an encryption header. While it is a useful global condition for network-level access control, such as allowing only traffic from a corporate VPN, it does not inspect HTTP headers like x-amz-server-side-encryption. An attacker with a permitted IP address could still upload unencrypted objects, so this key does not satisfy the requirement to enforce encryption at the bucket policy level.

  • ✗

    aws:RequestedRegion

    Why it's wrong here

    The aws:RequestedRegion condition key is wrong because it evaluates the AWS region to which the request is directed, not the encryption header. This key is typically used to restrict operations to specific regions—for example, to enforce data residency by denying requests that target a non-compliant region endpoint. It has no ability to read or validate the x-amz-server-side-encryption header on an S3 PUT request, so it cannot enforce encryption requirements regardless of how it is configured.

  • ✗

    kms:EncryptionContext

    Why it's wrong here

    The kms:EncryptionContext condition key is wrong because it is designed for use in KMS key policies and grants, not S3 bucket policies. It refers to the encryption context—a set of key-value pairs—that a caller passes to AWS KMS when using server-side encryption with KMS (SSE-KMS), and it is evaluated by the KMS service during cryptographic operations. S3 bucket policies do not support this condition key; S3 itself evaluates s3:x-amz-server-side-encryption, not the KMS encryption context, so this option cannot be used to enforce encryption in a bucket policy.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.