Courseiva
Data Protection →easyMultiple Choice

SCS-C02 Data Protection Practice Question

Network Topology
$ aws s3api get-bucket-encryptionbucket DOC-EXAMPLE-BUCKETRefer to the exhibit."ServerSideEncryptionConfiguration": {"Rules": ["ApplyServerSideEncryptionByDefault": {"SSEAlgorithm": "AES256"

Refer to the exhibit. A security engineer runs the command shown and gets the output. What does this output indicate about the bucket's encryption configuration?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The bucket has default encryption enabled using SSE-S3.

The output shows that default encryption is set to AES256, which corresponds to SSE-S3. This means new objects uploaded to the bucket will be encrypted with SSE-S3 unless a different encryption header is provided. Therefore, option D is correct. Option A is incorrect because the default encryption setting does not prevent unencrypted objects from being uploaded if the client does not provide encryption headers—it only applies encryption by default. Option B is incorrect because SSE-KMS uses a different key management service, not AES256. Option C is incorrect because default encryption does not require all objects to be encrypted with SSE-KMS; it sets a server-side default, but clients can override with their own encryption settings.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The bucket does not allow unencrypted objects.

    Why it's wrong here

    The output of get-bucket-encryption only reports the default encryption rule; it does not enforce or prove any admission policy. Default encryption means S3 automatically applies AES256 when an upload lacks encryption headers, but it does not actively reject unencrypted objects unless a bucket policy includes a Deny for s3:PutObject without the required encryption parameters. Therefore this statement misinterprets a bucket-level default as a security control.

  • ✗

    The bucket has default encryption enabled using SSE-KMS.

    Why it's wrong here

    The returned JSON contains "SSEAlgorithm": "AES256", which is the algorithm identifier for SSE-S3, not SSE-KMS. If the default were SSE-KMS, the field would be "aws:kms" and would usually be accompanied by a KMSMasterKeyID; neither appears in the output. Concluding that the bucket uses SSE-KMS therefore contradicts the exact algorithm value returned by the API.

  • ✗

    The bucket requires all objects to be encrypted with SSE-KMS.

    Why it's wrong here

    A default encryption rule is not a hard requirement that every object must use that algorithm; a client can still supply its own x-amz-server-side-encryption header, such as "aws:kms" or "AES256", and S3 honors the request header over the bucket default. Moreover, the output identifies AES256 (SSE-S3), so saying all objects must use SSE-KMS is doubly incorrect: it names the wrong key type and overstates the enforcement. A genuine SSE-KMS mandate would require an explicit bucket policy or IAM condition that denies s3:PutObject without the appropriate encryption header.

  • ✓

    The bucket has default encryption enabled using SSE-S3.

    Why this is correct

    The API response shows "ApplyServerSideEncryptionByDefault" with "SSEAlgorithm": "AES256", which directly maps to S3-managed keys, i.e., SSE-S3. With SSE-S3 default encryption enabled, any object uploaded without an encryption header is automatically encrypted at rest using S3's AES-256 encryption. This is exactly what the get-bucket-encryption output demonstrates, making this the correct interpretation.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.