SCS-C02 Data Protection Practice Question
Network Topology
A security engineer runs the command shown in the exhibit. What is the outcome?
⚠ Common exam trap
Candidates often confuse `AES256` with an invalid algorithm or assume it refers to SSE-KMS, but AWS specifically uses `AES256` as the identifier for SSE-S3, while `aws:kms` is used for SSE-KMS.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Default encryption is enabled on the bucket using SSE-S3.
The command `aws s3api put-bucket-encryption --bucket my-bucket --server-side-encryption-configuration '{"Rules":[{"ApplyServerSideEncryptionByDefault":{"SSEAlgorithm":"AES256"}}]}'` enables default encryption on the bucket using SSE-S3, because `AES256` is the algorithm identifier for SSE-S3 (Amazon S3-managed keys). The command succeeds and sets the default encryption configuration to use server-side encryption with S3-managed keys, which is the standard SSE-S3 behavior.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The command fails because AES256 is not a valid algorithm.
Why it's wrong here
The `SSEAlgorithm` value `AES256` is a valid, documented value in the Amazon S3 API for SSE-S3. For default encryption configuration, accepted algorithms are `AES256` (SSE-S3) and `aws:kms` (SSE-KMS) in the `ApplyServerSideEncryptionByDefault` rule. Therefore a command that sets or returns this value does not fail because of an invalid algorithm; it successfully represents SSE-S3 bucket encryption.
- ✓
Default encryption is enabled on the bucket using SSE-S3.
Why this is correct
Seeing `SSEAlgorithm: AES256` in the bucket encryption response means default encryption is enabled with SSE-S3, where Amazon S3 manages the encryption keys. This configuration causes new objects written to the bucket to be automatically encrypted at rest with 256-bit AES using S3-managed keys, and the setting is stored as a bucket-level default rather than applied individually per object.
- ✗
Default encryption is enabled on the bucket using SSE-KMS.
Why it's wrong here
SSE-KMS would appear as `aws:kms` in the SSEAlgorithm field, often accompanied by a `KMSMasterKeyID` ARN. Because the output shows `AES256` instead, the bucket is not using AWS KMS for default encryption, and any explanation attributing the setting to SSE-KMS misreads the API response.
- ✗
The command removes default encryption from the bucket.
Why it's wrong here
The retrieved configuration—or the successful completion of a put-bucket-encryption command—indicates that default encryption is actively present and enabled. Removing default encryption would require `delete-bucket-encryption`; after that, a subsequent `get-bucket-encryption` would return an error such as `ServerSideEncryptionConfigurationNotFoundError`, not a configuration object containing `AES256`.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.