Courseiva
Data Protection →mediumMultiple Choice

SCS-C02 Data Protection Practice Question

A company uses S3 to store sensitive customer data. They want to ensure that all S3 buckets have encryption enabled at rest. Which S3 feature should be used to automatically enforce encryption on all newly created objects?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

S3 Bucket Policy with a condition requiring server-side encryption

An S3 bucket policy with a condition requiring server-side encryption (e.g., 's3:x-amz-server-side-encryption': 'aws:kms' or 'AES256') can deny any PutObject request that does not include the encryption header, thereby automatically enforcing encryption on all newly created objects. Option A is incorrect because S3 Block Public Access controls public access, not encryption. Option B is incorrect because S3 Object Lock is for write-once-read-many (WORM) retention, not encryption enforcement. Option D is incorrect because S3 Inventory provides a list of objects and their metadata but does not enforce encryption.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    S3 Block Public Access

    Why it's wrong here

    S3 Block Public Access provides account- and bucket-level guardrails that block public reads/writes by overriding permissive bucket policies and ACLs, but it works strictly at the access-control layer. It never inspects upload headers or object metadata, so an IAM role or user with write access can still upload an object with no encryption configured. Therefore it can stop inadvertent public exposure but cannot satisfy a requirement to enforce encryption at rest.

  • ✗

    S3 Object Lock

    Why it's wrong here

    S3 Object Lock enforces a write-once-read-many (WORM) model by using retention periods in GOVERNANCE or COMPLIANCE mode and legal holds, preventing object versions from being deleted or overwritten. However, retention applies after the object exists and is independent of the storage encryption settings; an object can be locked and completely unencrypted at the same time. It addresses data integrity and compliance, but not the encryption policy.

  • ✓

    S3 Bucket Policy with a condition requiring server-side encryption

    Why this is correct

    A bucket policy can enforce server-side encryption by using the request header condition keys `s3:x-amz-server-side-encryption` and `s3:x-amz-server-side-encryption-aws-kms-key-id`. For instance, a `Deny` statement with `StringNotEquals` on `s3:x-amz-server-side-encryption` for `aws:kms`, combined with a `Null` condition that denies uploads where the header is absent, will reject every `PutObject` and `InitiateMultipartUpload` that does not specify SSE-KMS. This is a direct, request-time enforcement mechanism.

  • ✗

    S3 Inventory

    Why it's wrong here

    S3 Inventory generates scheduled CSV or Parquet reports listing all objects and their metadata, including encryption status, storage class, and size. It is a reporting and auditing tool only; it produces a point-in-time view after objects are written, so it can identify unencrypted objects for remediation but cannot block or reject an upload that lacks encryption headers. Inventory gives visibility, not control.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.