Courseiva

SOA-C02 Reliability and Business Continuity Practice Question

A company uses Amazon S3 to store backup data. The SysOps administrator needs to ensure that the data is encrypted at rest and that access is limited to only authorized users. Which TWO actions should be taken? (Choose TWO.)

⚠ Common exam trap

Watch out — candidates often confuse 'blocking public access' (a network-level control) with 'encryption at rest' (a data protection control), or think that versioning or transfer acceleration somehow addresses encryption or authorization requirements.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable default encryption on the S3 bucket using SSE-S3 or AWS KMS.

Enabling default encryption on the S3 bucket using SSE-S3 or AWS KMS ensures that all objects stored in the bucket are encrypted at rest automatically, meeting the encryption-at-rest requirement. This can be configured via the bucket properties, and it applies to any object uploaded without explicit encryption headers.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable default encryption on the S3 bucket using SSE-S3 or AWS KMS.

    Why this is correct

    Enabling default encryption on the S3 bucket with SSE-S3 or SSE-KMS ensures that every object written to the bucket is encrypted server-side at rest automatically, regardless of how it is uploaded. SSE-S3 uses AES-256 managed by Amazon, while SSE-KMS gives you customer-managed keys and separate audit permissions. This default setting satisfies compliance requirements for encrypted backups and prevents the accidental upload of plaintext objects.

  • ✗

    Block all public access to the S3 bucket.

    Why it's wrong here

    Blocking all public access is a foundational security best practice that prevents anonymous or public reads/writes, but it does not encrypt data or govern what authorized identities can do. The block public access settings cannot enforce that objects are encrypted, nor do they replace IAM or bucket policies that define access for specific users. As a result, data remains vulnerable to unauthorized access from compromised credentials or overly permissive policies.

  • ✓

    Create a bucket policy that allows only specific IAM roles or users.

    Why this is correct

    Creating a bucket policy that explicitly allows only specific IAM roles or users via the Principal element scopes access to known identities, so backups cannot be read, written, or deleted by anyone else inside or outside the company. This implements least-privilege access control, letting the SysOps administrator decide which actions and resources are accessible, and it can be combined with conditions like MFA or IP ranges. However, a bucket policy alone does not protect data at rest; it must be paired with default encryption to meet an encryption requirement.

  • ✗

    Enable S3 Versioning on the bucket.

    Why it's wrong here

    Enabling S3 Versioning preserves every version of an object, including overwritten or deleted versions, which helps protect against accidental changes and ransomware but does not add any encryption or access restriction. Versioning also increases storage costs and requires additional lifecycle management. It is useful for recovery, not for ensuring backup data is encrypted.

  • ✗

    Enable S3 Transfer Acceleration.

    Why it's wrong here

    S3 Transfer Acceleration uses AWS edge locations and optimized network paths to speed up large uploads over long distances, but it has no effect on encryption or access control. It only changes the data transfer path from the client to the bucket; the object remains stored as a standard S3 object once it arrives. Enabling acceleration does not encrypt data at rest or in transit beyond the normal HTTPS options, so it cannot meet an encryption requirement.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.