Courseiva
Security and Compliance →mediumMultiple Choice

SOA-C02 Security and Compliance Practice Question

A company requires all S3 uploads to use server-side encryption with a specific customer managed KMS key. What is the most direct enforcement mechanism?

⚠ Common exam trap

Candidates often confuse IAM permissions with bucket policy conditions, assuming that IAM policies alone can enforce encryption headers, when in fact only a bucket policy with the appropriate condition keys can directly deny uploads that lack the required encryption headers.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add a bucket policy that denies PutObject unless the required SSE-KMS headers and key ID are present.

A bucket policy with a condition that denies `s3:PutObject` unless the required `x-amz-server-side-encryption` header is set to `aws:kms` and the `x-amz-server-side-encryption-aws-kms-key-id` header matches the specific customer managed KMS key ARN is the most direct enforcement mechanism. This policy-based approach ensures that any upload attempt lacking the required SSE-KMS headers and key ID is rejected at the S3 API level, regardless of the IAM permissions of the uploader.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Add a bucket policy that denies PutObject unless the required SSE-KMS headers and key ID are present.

    Why this is correct

    A bucket policy with an explicit Deny on s3:PutObject can inspect the s3:x-amz-server-side-encryption and s3:x-amz-server-side-encryption-aws-kms-key-id condition keys. If the request lacks the required SSE-KMS header or uses a different KMS key ID, S3 returns 403 AccessDenied before accepting the upload. This enforces encryption at write time, making it the only option that guarantees every upload is encrypted with your designated KMS key.

  • ✗

    Enable S3 versioning only.

    Why it's wrong here

    S3 versioning stores multiple versions of an object, so if an unencrypted object is overwritten, the prior unencrypted version remains accessible as an older version. It does not evaluate or require the x-amz-server-side-encryption header on PutObject requests, and it has no effect on existing objects that were uploaded without encryption. Versioning alone therefore preserves data lifecycle but fails to meet the requirement that all uploads use server-side encryption.

  • ✗

    Enable S3 Transfer Acceleration.

    Why it's wrong here

    S3 Transfer Acceleration uses AWS edge locations and optimized network paths to speed up large uploads over long distances. It changes the transfer endpoint and routing but does not alter S3's request handling or object attributes, so a PutObject can still succeed without any encryption headers. Acceleration is purely a performance feature and cannot enforce SSE-KMS or any encryption policy.

  • ✗

    Create an IAM user for every uploader with console access.

    Why it's wrong here

    Creating a separate IAM user with console access for each uploader controls identity and permissions, but it does not restrict the parameters of a PutObject call. An IAM user can upload an object without SSE-KMS headers unless there is an additional policy, such as a Deny with the s3:x-amz-server-side-encryption condition, that explicitly prohibits it. Identity management alone cannot guarantee encryption of the uploaded content.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.