SCS-C02 Data Protection Practice Question
A security engineer needs to protect sensitive data stored in an Amazon S3 bucket. The data must be encrypted at rest using a customer managed key in AWS KMS, and the engineer wants to ensure that all requests to upload objects without encryption are automatically denied. The bucket is in account 111122223333. Which S3 bucket policy statement should the engineer use?
⚠ Common exam trap
The trap here is using an Allow statement instead of a Deny statement, or confusing the header value for SSE-S3 (AES256) with SSE-KMS (aws:kms).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A statement that denies s3:PutObject if the request lacks the s3:x-amz-server-side-encryption header with value aws:kms.
To enforce that all objects uploaded to an S3 bucket are encrypted with SSE-KMS, the bucket policy must include a Deny statement that blocks PutObject requests when the s3:x-amz-server-side-encryption header is missing or not set to aws:kms. This ensures that any upload without the required encryption header is rejected. Allow statements alone do not prevent non-compliant uploads, and conditions specifying AES256 enforce SSE-S3, not SSE-KMS.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A statement that denies s3:PutObject if the request includes the s3:x-amz-server-side-encryption header with value aws:kms.
Why it's wrong here
This policy denies uploads that use AWS KMS, which is the opposite of what is required. The company wants to enforce the use of AWS KMS, not block it. This would prevent compliant uploads and allow non-compliant ones, which is incorrect. The condition should check for the absence of the header or a different value to deny non-compliant requests.
- ✓
A statement that denies s3:PutObject if the request lacks the s3:x-amz-server-side-encryption header with value aws:kms.
Why this is correct
This policy uses a Deny effect with a condition that checks for the presence and value of the s3:x-amz-server-side-encryption header. If a PutObject request does not include the header with aws:kms, the request is denied. This enforces encryption with SSE-KMS for all uploads. It is the standard way to require a specific encryption method for objects uploaded to an S3 bucket.
- ✗
A statement that denies s3:PutObject if the request does not include the s3:x-amz-server-side-encryption header with value AES256.
Why it's wrong here
This policy would deny uploads that do not use AES256, but it does not enforce the use of AWS KMS. The requirement is to use a customer managed key in AWS KMS, which requires the aws:kms value. Using AES256 would result in SSE-S3 encryption, which does not use a customer managed key. Therefore, this policy does not meet the requirement.
- ✗
A statement that allows s3:PutObject only if the request includes the s3:x-amz-server-side-encryption header with value AES256.
Why it's wrong here
This statement allows uploads only when the header value is AES256, which enforces SSE-S3, not SSE-KMS. The requirement is to use a customer managed key in AWS KMS, which corresponds to the aws:kms value. Additionally, an Allow statement does not automatically deny requests that lack the header; it only allows those that meet the condition. A Deny statement is needed to block non-compliant uploads.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.