SCS-C02 Data Protection Practice Question
Network Topology
Refer to the exhibit. A security engineer runs the command shown and gets the output. What does this output indicate about the bucket's encryption configuration?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The bucket has default encryption enabled using SSE-S3.
The output shows that default encryption is set to AES256, which corresponds to SSE-S3. This means new objects uploaded to the bucket will be encrypted with SSE-S3 unless a different encryption header is provided. Therefore, option D is correct. Option A is incorrect because the default encryption setting does not prevent unencrypted objects from being uploaded if the client does not provide encryption headers—it only applies encryption by default. Option B is incorrect because SSE-KMS uses a different key management service, not AES256. Option C is incorrect because default encryption does not require all objects to be encrypted with SSE-KMS; it sets a server-side default, but clients can override with their own encryption settings.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The bucket does not allow unencrypted objects.
Why it's wrong here
The output of get-bucket-encryption only reports the default encryption rule; it does not enforce or prove any admission policy. Default encryption means S3 automatically applies AES256 when an upload lacks encryption headers, but it does not actively reject unencrypted objects unless a bucket policy includes a Deny for s3:PutObject without the required encryption parameters. Therefore this statement misinterprets a bucket-level default as a security control.
- ✗
The bucket has default encryption enabled using SSE-KMS.
Why it's wrong here
The returned JSON contains "SSEAlgorithm": "AES256", which is the algorithm identifier for SSE-S3, not SSE-KMS. If the default were SSE-KMS, the field would be "aws:kms" and would usually be accompanied by a KMSMasterKeyID; neither appears in the output. Concluding that the bucket uses SSE-KMS therefore contradicts the exact algorithm value returned by the API.
- ✗
The bucket requires all objects to be encrypted with SSE-KMS.
Why it's wrong here
A default encryption rule is not a hard requirement that every object must use that algorithm; a client can still supply its own x-amz-server-side-encryption header, such as "aws:kms" or "AES256", and S3 honors the request header over the bucket default. Moreover, the output identifies AES256 (SSE-S3), so saying all objects must use SSE-KMS is doubly incorrect: it names the wrong key type and overstates the enforcement. A genuine SSE-KMS mandate would require an explicit bucket policy or IAM condition that denies s3:PutObject without the appropriate encryption header.
- ✓
The bucket has default encryption enabled using SSE-S3.
Why this is correct
The API response shows "ApplyServerSideEncryptionByDefault" with "SSEAlgorithm": "AES256", which directly maps to S3-managed keys, i.e., SSE-S3. With SSE-S3 default encryption enabled, any object uploaded without an encryption header is automatically encrypted at rest using S3's AES-256 encryption. This is exactly what the get-bucket-encryption output demonstrates, making this the correct interpretation.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.