A company uses S3 to store sensitive customer data. They want to ensure that all S3 buckets have encryption enabled at rest. Which S3 feature should be used to automatically enforce encryption on all newly created objects?
A bucket policy can enforce server-side encryption by using the request header condition keys `s3:x-amz-server-side-encryption` and `s3:x-amz-server-side-encryption-aws-kms-key-id`. For instance, a `Deny` statement with `StringNotEquals` on `s3:x-amz-server-side-encryption` for `aws:kms`, combined with a `Null` condition that denies uploads where the header is absent, will reject every `PutObject` and `InitiateMultipartUpload` that does not specify SSE-KMS. This is a direct, request-time enforcement mechanism.
Why this answer
An S3 bucket policy with a condition requiring server-side encryption (e.g., 's3:x-amz-server-side-encryption': 'aws:kms' or 'AES256') can deny any PutObject request that does not include the encryption header, thereby automatically enforcing encryption on all newly created objects. Option A is incorrect because S3 Block Public Access controls public access, not encryption. Option B is incorrect because S3 Object Lock is for write-once-read-many (WORM) retention, not encryption enforcement.
Option D is incorrect because S3 Inventory provides a list of objects and their metadata but does not enforce encryption.