SOA-C02 Security and Compliance Practice Question
A company requires that all data stored in Amazon S3 be encrypted at rest. Which S3 feature should be enabled to meet this requirement without changing the application code?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable default encryption on the S3 bucket.
Enabling default encryption on the S3 bucket automatically encrypts all new objects at rest without requiring any application code changes. Option A (using a bucket policy to deny unencrypted uploads) can enforce encryption but does not encrypt the objects; it requires the application to include encryption headers, which would require code changes. Option C (S3 Object Lock) is a feature for preventing object deletion or overwrites, not for encryption. Option D (client-side encryption) requires modifying the application to encrypt data before upload, which does not meet the requirement of no code changes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use an S3 bucket policy to deny unencrypted uploads.
Why it's wrong here
A bucket policy can be authored with a condition that denies any s3:PutObject request lacking an encryption header, but this only blocks future unencrypted uploads. Objects that are already in the bucket remain unencrypted, and the policy does not proactively encrypt or rewrite any existing data, so it fails to guarantee that all stored objects are encrypted.
- ✓
Enable default encryption on the S3 bucket.
Why this is correct
Enabling default encryption on the S3 bucket configures it to apply server-side encryption with Amazon S3-managed keys (SSE-S3) automatically to any new object uploaded without an explicit encryption header. Existing objects are not encrypted automatically by this setting alone, but after enabling default encryption, you can copy those objects onto themselves to encrypt them, thereby satisfying the requirement for all data at rest.
- ✗
Enable S3 Object Lock.
Why it's wrong here
S3 Object Lock is a compliance feature that provides write-once-read-many (WORM) protection through retention periods and legal holds; it prevents objects from being deleted or overwritten. It does not perform any cryptographic operation or change how data is stored at rest, so enabling Object Lock leaves the objects unencrypted and therefore does not meet the stated encryption requirement.
- ✗
Use client-side encryption.
Why it's wrong here
Client-side encryption does encrypt objects before they are uploaded, but it requires the application to be modified to handle encryption and key management on every write, and it does nothing for objects that were already uploaded. Existing stored objects would remain unencrypted unless a separate process reads, encrypts, and re-uploads each one, making this a far less efficient and more complex solution than enabling default server-side encryption.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.