Courseiva
Infrastructure Security →easyMultiple Choice

SCS-C02 Infrastructure Security Practice Question

A security engineer needs to ensure that all Amazon EBS volumes attached to EC2 instances in a production account are encrypted at rest. The engineer wants to enforce this requirement automatically and prevent the creation of unencrypted volumes. Which action should the engineer take?

⚠ Common exam trap

The trap here is thinking that IAM policies or AWS Config are the primary enforcement mechanisms, when the simplest and most direct method is enabling encryption by default.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable EBS encryption by default in the AWS Region.

Enabling EBS encryption by default in the Region ensures that all new EBS volumes are automatically encrypted at rest. This is a simple, effective way to enforce encryption and prevent the creation of unencrypted volumes. It applies to all new volumes regardless of how they are created, providing a robust control.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Attach a bucket policy to the EBS service that requires encryption.

    Why it's wrong here

    EBS volumes are not S3 buckets, and bucket policies apply to S3. This option is not applicable. There is no bucket policy for EBS. The correct approach is to enable EBS encryption by default at the Region level.

  • ✓

    Enable EBS encryption by default in the AWS Region.

    Why this is correct

    Enabling EBS encryption by default ensures that all new EBS volumes created in the Region are automatically encrypted using the default KMS key for EBS encryption. This enforces encryption at rest without requiring manual intervention for each volume. It also prevents the creation of unencrypted volumes, meeting the requirement.

  • ✗

    Create an IAM policy that denies the ec2:CreateVolume action unless the encrypted parameter is true.

    Why it's wrong here

    An IAM policy can enforce encryption by denying the CreateVolume action if the encrypted parameter is not true, but this requires the policy to be attached to all principals that create volumes. It is not automatic for all volumes and can be bypassed if a principal has permission to modify the policy. Enabling encryption by default is simpler and more comprehensive.

  • ✗

    Use AWS Config to monitor for unencrypted volumes and automatically delete them.

    Why it's wrong here

    AWS Config can detect unencrypted volumes and trigger remediation, but it is reactive and may allow unencrypted volumes to exist temporarily. It does not prevent the creation of unencrypted volumes in the first place. The requirement is to enforce encryption automatically and prevent unencrypted volumes, which is better achieved by enabling encryption by default.

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.