Courseiva
Data Protection →mediumMultiple Select

SCS-C02 Data Protection Practice Question

A company wants to protect sensitive data stored in Amazon S3. Which TWO actions should the company take to meet this goal? (Choose TWO.)

⚠ Common exam trap

SCS-C02 often tests whether candidates confuse availability/performance features (Transfer Acceleration) or event-driven features (SNS notifications) with actual data protection controls, and whether they recognize that Object Lock addresses integrity/retention rather than confidentiality.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable S3 Block Public Access.

Option C (Enable S3 Block Public Access) is correct because it applies account- and bucket-level settings that reject any ACL or bucket policy granting public access, preventing accidental exposure of sensitive objects to the internet. Option E (Enable default encryption on the bucket) is correct because it ensures every object is encrypted at rest with SSE-S3 or SSE-KMS automatically, protecting data confidentiality even if storage media is compromised. Option A (S3 Transfer Acceleration) only speeds up uploads/downloads via edge locations and does not protect data. Option B (S3 event notifications to Amazon SNS) merely reports object events and provides no security control. Option D (S3 Object Lock) enforces WORM retention to prevent deletion or modification, which addresses integrity/retention rather than protecting sensitive data from unauthorized access or disclosure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable S3 Transfer Acceleration.

    Why it's wrong here

    S3 Transfer Acceleration speeds up data transfers by routing traffic over AWS edge locations and the global network backbone, but it only affects throughput and latency. It does not change permissions, encryption, or access control behavior, so it cannot prevent unauthorized parties from reading sensitive objects if permissions are misconfigured.

  • ✗

    Configure S3 event notifications to send events to Amazon SNS.

    Why it's wrong here

    S3 event notifications sent to Amazon SNS enable you to react to object lifecycle events such as creation, deletion, or restore completion, which is useful for triggering downstream workflows or alerts. This mechanism does not alter the bucket's access policies, ACLs, or encryption configuration, so it has no direct effect on preventing unauthorized access or confidentiality of stored data.

  • ✓

    Enable S3 Block Public Access.

    Why this is correct

    Enabling S3 Block Public Access adds a strong, explicit layer of protection that can block public reading or writing through bucket policies, ACLs, or object ACLs, even if those public grants are unintentionally set. This control operates at both bucket and account levels and is a primary safeguard against data exposure caused by misconfigurations, making it essential for sensitive data.

  • ✗

    Enable S3 Object Lock.

    Why it's wrong here

    S3 Object Lock enforces a write-once-read-many (WORM) model by applying retention periods and legal holds that prevent objects from being deleted or overwritten. While this is valuable for regulatory compliance and data integrity, it does nothing to stop an unauthorized user who can already read the object, and it does not restrict access permissions.

  • ✓

    Enable default encryption on the bucket.

    Why this is correct

    Enabling default encryption on an S3 bucket ensures every newly ingested object is automatically encrypted at rest using SSE-S3 or SSE-KMS, protecting data from physical theft or storage-media compromise. This protects confidentiality of the data at the storage layer, though it does not replace access controls since any party with valid permissions can still retrieve and decrypt the data through normal S3 APIs.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.