SOA-C02 Security and Compliance Practice Question
A company has an S3 bucket that stores sensitive data. The security team requires that all data be encrypted at rest and that all access be logged. Which TWO actions should the SysOps administrator take to meet these requirements? (Choose TWO.)
⚠ Common exam trap
SOA-C02 often tests whether candidates confuse adjacent S3 features (Transfer Acceleration, Replication, Object Lock) with the specific controls for encryption at rest and access logging, causing them to pick a feature that addresses a different requirement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable default encryption on the S3 bucket.
Option C is correct because enabling default encryption on the S3 bucket (using SSE-S3 or SSE-KMS) ensures that every object is automatically encrypted at rest when written, satisfying the requirement that all stored data be encrypted. Option E is correct because enabling S3 server access logs delivers detailed records of every request made to the bucket to a target logging bucket, which fulfills the requirement that all access be logged. Option A is incorrect because S3 Transfer Acceleration only speeds up uploads/downloads over long distances using edge locations; it does not provide encryption or logging. Option B is incorrect because S3 Replication copies objects to another bucket for durability, latency, or compliance purposes but does not itself encrypt data at rest or log access. Option D is incorrect because S3 Object Lock enforces WORM protection to prevent deletion or modification of objects, which is unrelated to encryption at rest or access logging.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable S3 Transfer Acceleration.
Why it's wrong here
S3 Transfer Acceleration uses AWS edge locations to accelerate uploads by routing data over optimized network paths, but it is purely a performance feature. It does not apply encryption to objects at rest, nor does it generate audit logs for bucket access. Sensitive data stored in S3 requires confidentiality and audit controls, not just faster transfer, so enabling it would not address the stated requirement.
- ✗
Enable S3 Replication to replicate objects to another bucket.
Why it's wrong here
S3 Replication asynchronously copies objects to another bucket, optionally in a different region, to support disaster recovery and lower latency access. It does not automatically encrypt the source or destination objects unless encryption is separately configured, and it does not record access requests for the original bucket. Replication may even create redundant copies that, if left unencrypted or unlogged, increase exposure, so it is not a direct security control for sensitive data.
- ✓
Enable default encryption on the S3 bucket.
Why this is correct
Enabling default encryption on the bucket ensures that every new object stored is automatically encrypted at rest using SSE-S3 (AES-256) or an SSE-KMS key, even when the upload request does not specify an encryption header. This protects sensitive data from physical media theft or unauthorized access to underlying storage infrastructure. It is a fundamental confidentiality control that should be paired with access logging and IAM policies to fully secure the data.
- ✗
Enable S3 Object Lock.
Why it's wrong here
S3 Object Lock implements a WORM (write-once-read-many) model that prevents objects from being deleted or overwritten for a specified retention period or until a legal hold is removed. It is useful for regulatory retention, not for protecting the confidentiality of sensitive data because it does not encrypt objects or log requests. Enabling Object Lock could actually complicate lifecycle management without providing any encryption or audit coverage.
- ✓
Enable S3 server access logs.
Why this is correct
S3 server access logs capture detailed records of every request made to the bucket, including requester identity, source IP, timestamp, HTTP method, target object, and response status. This audit trail is essential for detecting unauthorized access attempts, troubleshooting, and meeting compliance requirements. With sensitive data, access logging gives administrators visibility into who is accessing the data, so enabling it is a correct security control.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.