Courseiva

Enforcing S3 KMS Encryption — Bucket Policy and Default Encryption

A security engineer is implementing a data classification policy for an S3 bucket that contains sensitive customer data. The policy requires that all objects be encrypted at rest using AWS KMS and that any attempt to upload an unencrypted object be denied. Which THREE steps should the engineer take to enforce this policy? (Choose THREE.)

Quick Answer

Enable S3 default encryption with the KMS key completes a defense-in-depth strategy for enforcing encryption at rest, rather than acting alone as a silver-bullet control. A customer managed KMS key gives full control over rotation, access policies, and auditing; a bucket policy that denies PutObject unless the s3:x-amz-server-side-encryption header equals aws:kms rejects any upload that does not specify the right encryption; and default encryption acts as a safety net that automatically applies KMS encryption even if the uploader forgets to set the header, so nothing ever lands in the bucket unencrypted. The distinction worth holding onto is between deny-based and default-based enforcement: the bucket policy stops non-compliant requests outright, while default encryption quietly fixes requests that omit encryption instructions, together covering both the reject-bad-requests and auto-correct-missing-instructions cases. This is also why the other options fail: enabling bucket keys only reduces the number of KMS API calls for objects already being encrypted with KMS, it does nothing to enforce that encryption happens at all, and enforcing SSL/TLS only protects data in transit, a separate requirement from encryption at rest. When a question asks you to enforce a policy rather than simply enable a feature, look for the combination of a preventive control, a policy-level deny, and a default that closes any remaining gap.

⚠ Common exam trap

SCS-C02 often tests the difference between enabling default encryption (which is passive) and enforcing encryption via bucket policy (which is active). Candidates frequently select only default encryption and miss the need for an explicit deny policy to block unencrypted uploads.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a customer managed KMS key.

Option B is correct because the policy requires AWS KMS encryption, and a customer managed KMS key gives the engineer control over the key policy, rotation, and permissions needed to encrypt the sensitive objects. Option D is correct because a bucket policy with a Deny on s3:PutObject when the s3:x-amz-server-side-encryption condition is not aws:kms actively blocks any upload that does not request SSE-KMS, which is exactly the enforcement mechanism the policy demands. Option E is correct because enabling S3 default encryption with the KMS key ensures that objects are encrypted at rest with SSE-KMS even when a request does not explicitly specify encryption headers, satisfying the baseline encryption requirement. Option A is not correct because S3 Bucket Keys only reduce KMS API call costs and request throttling; they do not enforce encryption or deny unencrypted uploads. Option C is not correct because enforcing aws:SecureTransport only requires TLS in transit and does nothing to guarantee encryption at rest with KMS or to reject unencrypted object uploads.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable S3 bucket keys to reduce KMS API calls.

    Why it's wrong here

    Bucket keys only reduce KMS request costs and throttling by deriving a per-bucket key; they do not deny unencrypted PUTs. The requirement needs a bucket policy with s3:x-amz-server-side-encryption conditions. Bucket keys are tempting because they cut KMS API calls, and they would be correct when KMS throttling or cost is the concern.

  • ✓

    Create a customer managed KMS key.

    Why this is correct

    A customer managed KMS key provides the key material and granular key policy control required for SSE-KMS encryption of the sensitive objects. Without it, the bucket policy condition on aws:kms cannot be satisfied, since no suitable key exists to reference.

  • ✗

    Enable bucket policy to enforce SSL (aws:SecureTransport).

    Why it's wrong here

    aws:SecureTransport enforces TLS in transit, not encryption at rest, so unencrypted objects could still be stored. Denying uploads requires a bucket policy condition on s3:x-amz-server-side-encryption. It is tempting because the policy does restrict uploads, and it would be correct when the requirement is HTTPS-only access to the bucket.

  • ✓

    Add a bucket policy that denies PutObject if s3:x-amz-server-side-encryption is not aws:kms.

    Why this is correct

    A bucket policy denying PutObject when s3:x-amz-server-side-encryption is absent or not aws:kms enforces the policy at the API layer, rejecting unencrypted uploads regardless of client behaviour. This satisfies the requirement that any attempt to upload an unencrypted object be denied, and mandates AWS KMS as the encryption mechanism.

  • ✓

    Enable S3 default encryption with the KMS key.

    Why this is correct

    Enabling default encryption with the KMS key ensures every object written without explicit encryption headers is still encrypted using that key, closing the gap left by header-based policies alone. It satisfies the at-rest KMS requirement for all uploads.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SCS-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A security engineer is designing a data encryption strategy for an S3 bucket that contains sensitive information. Which TWO of the following are valid options for enforcing encryption at rest?

medium
  • A.Use an AWS KMS key with automatic key rotation.
  • ✓ B.Enable S3 default encryption on the bucket.
  • C.Enable AWS CloudTrail to log all object uploads.
  • D.Attach an IAM policy to users to require encryption.
  • ✓ E.Use a bucket policy to deny PutObject requests without the x-amz-server-side-encryption header.

Why B: Option B is correct because S3 default encryption (SSE-S3, SSE-KMS, or DSSE-KMS) automatically encrypts every object at rest when it is written to the bucket, so no per-request header is required and enforcement is applied at the bucket level. Option E is correct because a bucket policy that denies s3:PutObject when the s3:x-amz-server-side-encryption condition key is absent (or does not match an approved algorithm such as AES256 or aws:kms) blocks unencrypted uploads, effectively enforcing encryption at rest for all writers. Option A is not a valid enforcement mechanism by itself: a KMS key with automatic rotation strengthens key hygiene but does not force objects to be encrypted unless default encryption or a policy requires that key. Option C is wrong because CloudTrail only records API activity for auditing; it does not encrypt data or prevent unencrypted uploads. Option D is wrong because an IAM policy attached to users is not the recommended or reliable enforcement point for bucket-level encryption, since it can be bypassed by other principals and does not apply to the bucket itself.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.