SOA-C02 Security and Compliance Practice Question
A company is using AWS Organizations with multiple accounts. The security team wants to ensure that all new S3 buckets created in any account have encryption enabled. Which approach should be used to enforce this policy?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a service control policy (SCP) that denies the s3:CreateBucket action unless the request includes the x-amz-server-side-encryption header with a valid encryption algorithm.
Service Control Policies (SCPs) in AWS Organizations allow central governance to deny actions across all accounts. An SCP can deny the s3:CreateBucket action unless the request includes the server-side-encryption header, thus enforcing encryption on new buckets. Option B is incorrect because IAM roles per account lack centralized enforcement and cannot prevent users with their own permissions from creating buckets without encryption. Option C is incorrect because AWS Config rules are detective, not preventive; they can only detect and optionally remediate after the bucket is created, not block the creation. Option D is incorrect because using CloudTrail and CloudWatch Events with a Lambda function is a reactive approach—it can delete a non-compliant bucket after creation, but does not enforce encryption at the time of creation. The requirement is to enforce the policy, making a preventive SCP the correct solution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a service control policy (SCP) that denies the s3:CreateBucket action unless the request includes the x-amz-server-side-encryption header with a valid encryption algorithm.
Why this is correct
A service control policy (SCP) attached at the organization or organizational unit level can deny the s3:CreateBucket action unless the request includes an x-amz-server-side-encryption header, using the s3:x-amz-server-side-encryption condition key. Because SCPs apply to every IAM principal in the account—including the root user—they provide a central, preventive guardrail that blocks the API call entirely, rather than merely auditing or remediating after the fact.
- ✗
Create an IAM role in each member account with a policy that denies s3:CreateBucket without encryption, and require all users to assume that role.
Why it's wrong here
This approach requires every user to assume a specific IAM role, but it does not prevent users with their own IAM permissions or administrative privileges from directly calling s3:CreateBucket without that role. IAM roles are per-account and do not provide central governance across the organization, leaving each member account to manage its own role and trust policy. Moreover, the role's deny policy can be bypassed if a user has an explicit allow for s3:CreateBucket from another policy.
- ✗
Use AWS Config managed rule 's3-bucket-server-side-encryption-enabled' to detect non-compliant buckets and automatically remediate.
Why it's wrong here
The AWS Config managed rule 's3-bucket-server-side-encryption-enabled' is a detective control that evaluates whether existing buckets have default encryption enabled, but it cannot stop the initial CreateBucket API call. Automatic remediation via Systems Manager Automation or custom Lambda functions can fix non-compliant resources after they are created, but there is a delay between detection and remediation, leaving a temporary compliance gap. This approach fails to prevent the bucket from being created in the first place, which is the requirement.
- ✗
Enable AWS CloudTrail and create a CloudWatch Events rule that triggers a Lambda function to delete any bucket created without encryption.
Why it's wrong here
Setting up CloudTrail with a CloudWatch Events rule that triggers a Lambda function to delete non-compliant buckets is inherently reactive. There is a latency window after the bucket is created and before the event is processed, during which the bucket exists and may be used or accessed, and deletion could cause data loss if objects are added immediately. Additionally, the Lambda function might lack the necessary permissions or the deletion could fail, leaving non-compliant resources in place indefinitely. This cannot satisfy a preventive control requirement.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.