How to Enable Default SSE-KMS Encryption on an S3 Bucket
Network Topology
Refer to the exhibit. A security engineer is reviewing the bucket encryption configuration. The bucket is used to store sensitive data. The company policy requires that all objects be encrypted using AWS KMS with a customer managed key. What should the engineer do to meet the policy?
Quick Answer
The correct answer is to update the bucket encryption configuration to use SSEAlgorithm: aws:kms and specify a KMS key ID. This is necessary because the current bucket is using SSE-S3 (AES256), which encrypts objects with an Amazon S3-managed key, but the company policy requires server-side encryption with a customer managed key under AWS KMS. By changing the default encryption settings to aws:kms and providing the specific KMS key ID, the bucket will automatically apply SSE-KMS to all new objects, meeting the compliance requirement. On the AWS Certified Security Specialty SCS-C02 exam, this scenario tests your understanding of the difference between SSE-S3, SSE-KMS, and SSE-C, and the common trap is confusing bucket policies with default encryption settings—specifying a KMS key in a bucket policy does not enforce encryption on uploads. A helpful memory tip is: “Default encryption is the enforcer; bucket policy is the gatekeeper.”
⚠ Common exam trap
The trap is equating 'encrypted at rest' with 'KMS customer managed key' — SSE-S3 also encrypts at rest but gives the customer no control over key rotation, which is the actual policy requirement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Update the bucket encryption configuration to use SSEAlgorithm: aws:kms and specify a KMS key ID
The company policy requires AWS KMS with a customer managed key, which corresponds to SSE-KMS with SSEAlgorithm set to aws:kms and an explicit KMS key ID (or ARN) in the bucket's default encryption configuration. Updating the bucket encryption configuration via PutBucketEncryption with the KMS key ARN satisfies the requirement for all newly uploaded objects.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable the bucket key and set SSEAlgorithm to AES256
Why it's wrong here
Still uses SSE-S3, not KMS.
- ✗
Use client-side encryption with a KMS key
Why it's wrong here
Client-side encryption is not server-side.
- ✓
Update the bucket encryption configuration to use SSEAlgorithm: aws:kms and specify a KMS key ID
Why this is correct
Changes default encryption to SSE-KMS.
- ✗
Add a bucket policy that requires kms:Encrypt permission for all PutObject requests
Why it's wrong here
Does not enforce SSE-KMS default.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SCS-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company stores sensitive documents in an S3 bucket. The security team wants to ensure that any object uploaded to the bucket is automatically encrypted using server-side encryption with AWS KMS. Which S3 bucket feature should be configured?
easy- ✓ A.Default encryption
- B.Versioning
- C.Bucket policy
- D.Lifecycle policy
Why A: S3 default encryption (now called default encryption with SSE-KMS or SSE-S3) automatically encrypts every object at rest when it is uploaded, without requiring the uploader to specify encryption headers. Configuring default encryption with SSE-KMS using a customer-managed KMS key satisfies the requirement for automatic server-side encryption with AWS KMS. This is a bucket-level setting applied at PUT time.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.