SOA-C02 Security and Compliance Practice Question
A company has an S3 bucket that stores sensitive data. The security team requires that all access to the bucket be encrypted in transit. Which TWO actions should be taken to enforce this requirement? (Choose two.)
⚠ Common exam trap
It's easy for candidates to confuse encryption at rest (SSE-S3) with encryption in transit (HTTPS/SSL), leading candidates to select default encryption instead of the bucket policy condition or monitoring approach.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable AWS CloudTrail to log all S3 API calls and set up a CloudWatch alarm for any HTTP access
Enabling AWS CloudTrail to log all S3 API calls and setting up a CloudWatch alarm for any HTTP access allows the security team to detect and alert on any access that is not encrypted in transit (i.e., HTTP instead of HTTPS). This provides monitoring and incident response capability to enforce the encryption-in-transit requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable default encryption (SSE-S3) on the bucket
Why it's wrong here
Default encryption (SSE-S3) encrypts objects at rest with AES-256 but has no effect on data as it travels between clients and the bucket. Since the requirement is to prevent plaintext HTTP transmissions, enabling SSE-S3 alone does not block or detect cleartext requests. An intercepting party could still read sensitive data in transit, so this fails to meet the stated security goal.
- ✗
Enable S3 Transfer Acceleration
Why it's wrong here
S3 Transfer Acceleration improves upload speed by routing traffic through optimized AWS edge locations, and it does transport data over TLS. However, it does not enforce that clients use HTTPS for their requests; a client can still connect via HTTP to the standard S3 endpoint or even the accelerated endpoint. The feature is designed for performance, not protocol security, so it cannot guarantee HTTPS-only access.
- ✓
Enable AWS CloudTrail to log all S3 API calls and set up a CloudWatch alarm for any HTTP access
Why this is correct
CloudTrail logs every S3 API call, and the event record includes the aws:SecureTransport flag, which distinguishes HTTPS from HTTP. A CloudWatch alarm on that flag lets the company immediately detect and respond to any plaintext request. As a detective control, it does not block the request at the time, but it satisfies the requirement by enabling continuous monitoring for HTTPS-only access.
- ✓
Create an S3 bucket policy that denies s3:GetObject and s3:PutObject if the aws:SecureTransport condition is false
Why this is correct
A bucket policy that denies s3:GetObject and s3:PutObject when aws:SecureTransport is false is a direct preventive control. S3 evaluates this policy before fulfilling the request, so HTTP requests are rejected outright and never reach the object. This ensures that all access to sensitive data occurs over HTTPS, which is exactly the desired outcome.
- ✗
Use S3 VPC endpoints
Why it's wrong here
S3 VPC endpoints (gateway type) route traffic from a VPC to S3 without going over the public internet, but they do not inherently mandate TLS. The endpoint simply provides a private network path; clients can still make HTTP requests to S3 over that path, or via the public endpoint. To enforce HTTPS, you still need a bucket policy or client-side requirement, so this alone is insufficient.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.