Courseiva
Security and Compliance →mediumMultiple Choice

SOA-C02 Security and Compliance Practice Question

A company's security policy requires that all new Amazon S3 buckets must have server-side encryption with AWS Key Management Service (SSE-KMS) enabled by default. A SysOps administrator wants to enforce this requirement for all current and future S3 buckets in the account. Which AWS service or feature should be used to automatically apply this configuration?

⚠ Common exam trap

Watch out — candidates often confuse S3 default encryption (which is bucket-level only) with account-level enforcement, or they mistakenly think SCPs can directly enable encryption rather than just deny actions, leading them to pick options that are reactive or misaligned with the requirement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use AWS Config with the 's3-bucket-server-side-encryption-enabled' managed rule and configure automatic remediation to apply SSE-KMS when a non-compliant bucket is detected.

AWS Config with the 's3-bucket-server-side-encryption-enabled' managed rule can evaluate S3 buckets for compliance with server-side encryption requirements. When a non-compliant bucket is detected, automatic remediation can be configured to apply SSE-KMS using an AWS Systems Manager Automation document, ensuring all current and future buckets meet the security policy without manual intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable S3 default encryption at the account level in the S3 console.

    Why it's wrong here

    Amazon S3 does not offer an account-level default encryption setting; encryption defaults are configured per bucket, not once for an entire account. The S3 console only allows you to enable default encryption by selecting an individual bucket and editing its properties. Therefore this action cannot enforce encryption across all existing and future buckets, because it simply cannot be performed at the account level.

  • ✗

    Create an AWS CloudTrail trail that captures S3 API calls and triggers a Lambda function to enable encryption on any bucket that is created without it.

    Why it's wrong here

    CloudTrail records S3 data and management events but does not natively invoke Lambda; you would need an additional EventBridge or CloudWatch Logs rule to trigger a custom Lambda function. This approach is purely reactive, requiring custom code to parse events and call PutBucketEncryption, and it does nothing about buckets that already exist unless you build a separate audit and remediation workflow. It is not a managed, declarative solution like AWS Config automatic remediation.

  • ✗

    Use an AWS Organizations Service Control Policy (SCP) to deny the s3:PutBucketPublicAccessBlock action, forcing users to enable encryption.

    Why it's wrong here

    SCPs are permission guardrails that restrict the maximum allowed actions for IAM principals, and they cannot directly modify or configure the encryption settings of S3 buckets. Denying s3:PutBucketPublicAccessBlock is irrelevant to encryption and actually prevents users from changing public access settings, which is neither required nor sufficient for SSE-KMS. Moreover, SCPs do not remediate existing noncompliant resources; they only deny future API operations.

  • ✓

    Use AWS Config with the 's3-bucket-server-side-encryption-enabled' managed rule and configure automatic remediation to apply SSE-KMS when a non-compliant bucket is detected.

    Why this is correct

    AWS Config can evaluate all buckets (current and future) against the rule. Automatic remediation can invoke an SSM Automation document or a Lambda function to enable SSE-KMS on the bucket, meeting the requirement with a managed service.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

5 more ways this is tested on SOA-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company's security policy requires that all Amazon S3 buckets must be encrypted at rest using server-side encryption with Amazon S3 managed keys (SSE-S3). A SysOps administrator needs to automatically detect any bucket that does not have encryption enabled and automatically apply SSE-S3 encryption. The solution should leverage AWS managed services and minimize custom code. Which combination of AWS services should be used?

medium
  • ✓ A.AWS Config and AWS Lambda
  • B.Amazon GuardDuty and AWS Lambda
  • C.AWS CloudTrail and Amazon EventBridge
  • D.Amazon Macie and AWS Step Functions

Why A: AWS Config can evaluate S3 bucket configurations against a managed rule (s3-bucket-server-side-encryption-enabled) to detect non-compliant buckets. When a non-compliant bucket is detected, AWS Config can trigger an AWS Lambda function via an Amazon EventBridge rule or a custom remediation action to automatically enable SSE-S3 encryption on the bucket. This combination uses managed services and minimizes custom code, meeting the security policy requirement.

Variation 2. A company's security policy requires that all Amazon S3 buckets must be encrypted at rest with AWS Key Management Service (AWS KMS) customer managed keys. A SysOps administrator discovers that some buckets are not encrypted. Which combination of AWS services should be used to automatically detect and remediate non-compliant buckets using infrastructure as code?

hard
  • ✓ A.AWS Config with a managed rule and AWS Lambda for automatic remediation.
  • B.AWS CloudTrail and Amazon GuardDuty.
  • C.Amazon Inspector and AWS Systems Manager.
  • D.Amazon Macie and AWS CloudFormation.

Why A: AWS Config with a managed rule (e.g., s3-bucket-server-side-encryption-enabled) can continuously evaluate S3 buckets for compliance with the encryption policy. When a non-compliant bucket is detected, AWS Config can automatically invoke an AWS Lambda function to remediate the issue, such as enabling encryption with a customer managed KMS key. This combination provides automated detection and remediation using infrastructure as code, as the Config rule and Lambda function can be defined in AWS CloudFormation or similar IaC tools.

Variation 3. A company's security policy requires that all Amazon S3 buckets must have server-side encryption (SSE-S3 or SSE-KMS) enabled. The SysOps administrator needs to automatically detect any bucket that does not have encryption enabled and remediate it by enabling SSE-S3. Which AWS service should be used to implement this automated compliance enforcement?

medium
  • ✓ A.AWS Config
  • B.Amazon Inspector
  • C.AWS Trusted Advisor
  • D.Amazon Macie

Why A: AWS Config is the correct service because it provides managed rules (e.g., s3-bucket-server-side-encryption-enabled) that can continuously evaluate S3 bucket configurations against the security policy. When a non-compliant bucket is detected, AWS Config can trigger an automatic remediation action via Systems Manager Automation to enable SSE-S3, enforcing compliance without manual intervention.

Variation 4. A company's security policy requires that all Amazon S3 buckets must have server-side encryption with AWS Key Management Service (SSE-KMS) enabled. The SysOps administrator needs to automatically detect any existing or new S3 bucket that does not have SSE-KMS enabled and automatically apply the encryption configuration. The solution must use managed AWS services with minimal custom code. Which combination of AWS services should be used?

medium
  • ✓ A.Use AWS Config with a custom rule backed by an AWS Lambda function that checks if the S3 bucket has default SSE-KMS encryption enabled, and auto-remediates by enabling SSE-KMS default encryption (e.g., calling the PutBucketEncryption API).
  • B.Enable default encryption on the AWS account's S3 buckets using an S3 account-level setting in the S3 console, which automatically applies SSE-KMS to all new buckets.
  • C.Create an AWS CloudTrail event that triggers an AWS Lambda function when a bucket is created, and the Lambda applies SSE-KMS encryption. Use AWS Config to periodically scan existing buckets and apply encryption.
  • D.Use AWS Identity and Access Management (IAM) with a Service Control Policy (SCP) that denies any S3 bucket creation without SSE-KMS enabled, and use AWS Config to detect and notify on non-compliance.

Why A: It uses AWS Config with a custom Lambda-backed rule to detect non-compliant S3 buckets (those missing SSE-KMS) and auto-remediate by calling the PutBucketEncryption API to enable default SSE-KMS encryption on the bucket. This satisfies the requirement for minimal custom code (only the Lambda function) and uses managed AWS services (AWS Config, Lambda, S3) to automatically detect and fix both existing and new buckets, ensuring that all S3 buckets have SSE-KMS enabled as per the security policy.

Variation 5. An organization requires that all Amazon S3 buckets be encrypted at rest by default. A SysOps administrator needs to enforce this using AWS Config. Which AWS Config managed rule should be used?

medium
  • ✓ A.s3-bucket-encryption-enabled
  • B.s3-bucket-ssl-requests-only
  • C.s3-bucket-public-read-prohibited
  • D.s3-bucket-logging-enabled

Why A: The AWS Config managed rule `s3-bucket-encryption-enabled` checks whether S3 buckets have default encryption enabled (SSE-S3, SSE-KMS, or SSE-C). This directly enforces the requirement that all buckets are encrypted at rest by default, as it evaluates each bucket's encryption configuration and flags non-compliant resources.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.