SCS-C02 Data Protection Practice Question
A company uses S3 to store sensitive customer data. They want to ensure that all S3 buckets have encryption enabled at rest. Which S3 feature should be used to automatically enforce encryption on all newly created objects?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
S3 Bucket Policy with a condition requiring server-side encryption
An S3 bucket policy with a condition requiring server-side encryption (e.g., 's3:x-amz-server-side-encryption': 'aws:kms' or 'AES256') can deny any PutObject request that does not include the encryption header, thereby automatically enforcing encryption on all newly created objects. Option A is incorrect because S3 Block Public Access controls public access, not encryption. Option B is incorrect because S3 Object Lock is for write-once-read-many (WORM) retention, not encryption enforcement. Option D is incorrect because S3 Inventory provides a list of objects and their metadata but does not enforce encryption.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
S3 Block Public Access
Why it's wrong here
S3 Block Public Access provides account- and bucket-level guardrails that block public reads/writes by overriding permissive bucket policies and ACLs, but it works strictly at the access-control layer. It never inspects upload headers or object metadata, so an IAM role or user with write access can still upload an object with no encryption configured. Therefore it can stop inadvertent public exposure but cannot satisfy a requirement to enforce encryption at rest.
- ✗
S3 Object Lock
Why it's wrong here
S3 Object Lock enforces a write-once-read-many (WORM) model by using retention periods in GOVERNANCE or COMPLIANCE mode and legal holds, preventing object versions from being deleted or overwritten. However, retention applies after the object exists and is independent of the storage encryption settings; an object can be locked and completely unencrypted at the same time. It addresses data integrity and compliance, but not the encryption policy.
- ✓
S3 Bucket Policy with a condition requiring server-side encryption
Why this is correct
A bucket policy can enforce server-side encryption by using the request header condition keys `s3:x-amz-server-side-encryption` and `s3:x-amz-server-side-encryption-aws-kms-key-id`. For instance, a `Deny` statement with `StringNotEquals` on `s3:x-amz-server-side-encryption` for `aws:kms`, combined with a `Null` condition that denies uploads where the header is absent, will reject every `PutObject` and `InitiateMultipartUpload` that does not specify SSE-KMS. This is a direct, request-time enforcement mechanism.
- ✗
S3 Inventory
Why it's wrong here
S3 Inventory generates scheduled CSV or Parquet reports listing all objects and their metadata, including encryption status, storage class, and size. It is a reporting and auditing tool only; it produces a point-in-time view after objects are written, so it can identify unencrypted objects for remediation but cannot block or reject an upload that lacks encryption headers. Inventory gives visibility, not control.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.