Courseiva
Data Protection →easyMultiple Choice

SCS-C02 Data Protection Practice Question

Network Topology
aws s3api put-bucket-encryptionbucket my-bucketserver-side-encryption-configuration '{"Rules":[{"ApplyServerSideEncryptionByDefault":{"SSEAlgorithm":"AES256"}}]}'Refer to the exhibit.

A security engineer runs the command shown in the exhibit. What is the outcome?

⚠ Common exam trap

Candidates often confuse `AES256` with an invalid algorithm or assume it refers to SSE-KMS, but AWS specifically uses `AES256` as the identifier for SSE-S3, while `aws:kms` is used for SSE-KMS.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Default encryption is enabled on the bucket using SSE-S3.

The command `aws s3api put-bucket-encryption --bucket my-bucket --server-side-encryption-configuration '{"Rules":[{"ApplyServerSideEncryptionByDefault":{"SSEAlgorithm":"AES256"}}]}'` enables default encryption on the bucket using SSE-S3, because `AES256` is the algorithm identifier for SSE-S3 (Amazon S3-managed keys). The command succeeds and sets the default encryption configuration to use server-side encryption with S3-managed keys, which is the standard SSE-S3 behavior.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The command fails because AES256 is not a valid algorithm.

    Why it's wrong here

    The `SSEAlgorithm` value `AES256` is a valid, documented value in the Amazon S3 API for SSE-S3. For default encryption configuration, accepted algorithms are `AES256` (SSE-S3) and `aws:kms` (SSE-KMS) in the `ApplyServerSideEncryptionByDefault` rule. Therefore a command that sets or returns this value does not fail because of an invalid algorithm; it successfully represents SSE-S3 bucket encryption.

  • ✓

    Default encryption is enabled on the bucket using SSE-S3.

    Why this is correct

    Seeing `SSEAlgorithm: AES256` in the bucket encryption response means default encryption is enabled with SSE-S3, where Amazon S3 manages the encryption keys. This configuration causes new objects written to the bucket to be automatically encrypted at rest with 256-bit AES using S3-managed keys, and the setting is stored as a bucket-level default rather than applied individually per object.

  • ✗

    Default encryption is enabled on the bucket using SSE-KMS.

    Why it's wrong here

    SSE-KMS would appear as `aws:kms` in the SSEAlgorithm field, often accompanied by a `KMSMasterKeyID` ARN. Because the output shows `AES256` instead, the bucket is not using AWS KMS for default encryption, and any explanation attributing the setting to SSE-KMS misreads the API response.

  • ✗

    The command removes default encryption from the bucket.

    Why it's wrong here

    The retrieved configuration—or the successful completion of a put-bucket-encryption command—indicates that default encryption is actively present and enabled. Removing default encryption would require `delete-bucket-encryption`; after that, a subsequent `get-bucket-encryption` would return an error such as `ServerSideEncryptionConfigurationNotFoundError`, not a configuration object containing `AES256`.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.