SCS-C02 Infrastructure Security Practice Question
A security engineer needs to ensure that all Amazon S3 buckets in an AWS account have server-side encryption (SSE) enabled. The engineer wants to automatically remediate any bucket that is created without SSE. Which solution should the engineer implement?
⚠ Common exam trap
SCS-C02 often tests the distinction between preventive controls (SCPs, bucket policies, IAM) and detective-plus-remediation controls (AWS Config + SSM Automation) — candidates pick SCPs or bucket policies because they sound like 'enforcement' but they cannot automatically remediate existing resources.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use AWS Config with a managed rule (s3-bucket-server-side-encryption-enabled) and an automatic remediation action.
AWS Config's managed rule s3-bucket-server-side-encryption-enabled continuously evaluates every S3 bucket in the account and flags any that lack default encryption. Pairing it with an automatic remediation action (typically an SSM Automation document such as AWS-EnableS3BucketEncryption) means newly created non-compliant buckets are remediated without human intervention, satisfying the 'automatically remediate' requirement. This is the canonical AWS-native pattern for continuous compliance enforcement on S3.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use S3 bucket policies to deny access to objects without encryption.
Why it's wrong here
S3 bucket policies are resource-based policies that control access to objects and bucket operations. While you can write a condition that denies `s3:PutObject` when encryption headers are missing, this only governs data-plane requests; it does not evaluate or enforce the bucket's default encryption configuration at creation time. Because bucket policies do not apply to the `s3:CreateBucket` action or check for the `BucketEncryption` property, they cannot ensure that every bucket itself has SSE enabled.
- ✗
Apply an IAM policy that requires SSE for all S3 actions.
Why it's wrong here
IAM policies are identity-based and attach to users, groups, or roles, not to resources like S3 buckets. Although you can require the `s3:x-amz-server-side-encryption` condition on object write calls, this cannot enforce encryption on the bucket's configuration or on the `CreateBucket` call, which does not expose an encryption parameter to IAM. To truly cover all S3 actions, the policy would have to be attached to every principal and service role, and it still wouldn't remediate existing buckets.
- ✓
Use AWS Config with a managed rule (s3-bucket-server-side-encryption-enabled) and an automatic remediation action.
Why this is correct
AWS Config's managed rule `s3-bucket-server-side-encryption-enabled` continuously evaluates each S3 bucket for the presence of server-side encryption. When a bucket is found non-compliant, an automatic remediation action—typically a Systems Manager Automation document that calls `PutBucketEncryption`—is invoked to enable default encryption on that bucket. This provides a closed loop that both detects drift and corrects it for existing and newly created buckets, making it the only option that satisfies 'ensure all S3 buckets' proactively and reactively.
- ✗
Create a service control policy (SCP) that denies creation of buckets without encryption.
Why it's wrong here
An SCP is an organization-wide policy that restricts what IAM principals can do, and you can attach one that denies `s3:CreateBucket` unless the request includes a `BucketEncryption` parameter. However, SCPs are purely prohibitive—they only block new bucket creation and never act on buckets that already exist without encryption. Additionally, SCPs do not provide any feedback or automatic correction when a bucket is misconfigured by another mechanism, so they fall short of a complete assurance control.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.