Courseiva
Security and Compliance →hardMultiple Choice

SOA-C02 Security and Compliance Practice Question

A company uses AWS CloudTrail to log all API calls. The security team requires that all logs be encrypted at rest and stored in an S3 bucket that blocks public access. The SysOps administrator configures the bucket with default encryption (SSE-S3) and a bucket policy that denies all actions unless the request includes the x-amz-server-side-encryption header with value AES256. However, CloudTrail delivery fails. What is the MOST likely cause?

⚠ Common exam trap

Candidates often assume default encryption automatically satisfies encryption requirements, but bucket policy conditions are evaluated before S3 applies default encryption, so the missing header still causes a denial.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The bucket policy requires the x-amz-server-side-encryption header, but CloudTrail does not include this header

CloudTrail does not include the x-amz-server-side-encryption header when delivering log files to S3. The bucket policy requires this header for all PutObject requests, so CloudTrail's PUT requests are denied, causing delivery to fail. SSE-S3 encryption is applied automatically by S3 when default encryption is enabled, but the policy condition overrides that by requiring the header explicitly.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The bucket policy requires the x-amz-server-side-encryption header, but CloudTrail does not include this header

    Why this is correct

    CloudTrail delivers log files to S3 with SSE-S3 encryption applied automatically, but its PutObject requests do not include an x-amz-server-side-encryption header. The bucket policy in this scenario uses a condition that requires that exact header on all writes (e.g., s3:x-amz-server-side-encryption equals AES256). Because CloudTrail omits the header, the condition evaluates to false and the bucket policy denies the request, so log delivery fails even though the object would have been encrypted server-side.

  • ✗

    CloudTrail does not support SSE-S3 encryption

    Why it's wrong here

    CloudTrail fully supports SSE-S3 encryption; in fact, it encrypts all delivered log files with Amazon S3-managed keys by default. Some administrators mistakenly believe CloudTrail cannot work with SSE-S3 because it does not explicitly set the encryption header, but that is not the case. CloudTrail simply relies on S3's default behavior to apply SSE-S3 to the object, so the service is compatible with SSE-S3 without any additional configuration.

  • ✗

    The bucket policy does not grant CloudTrail the s3:PutObject permission

    Why it's wrong here

    The bucket policy does not lack a s3:PutObject permission for CloudTrail; actually, CloudTrail delivery relies on a bucket policy that grants it the needed write access, often along with s3:GetBucketAcl to validate ownership. In this failure, the policy explicitly permits s3:PutObject but then includes a condition that requires a specific encryption header. Because the condition is not met, the request is denied by that condition, not by an absent permission—if it were purely a missing permission, the diagnosis and fix would be different.

  • ✗

    The bucket has default encryption enabled, which conflicts with CloudTrail's encryption

    Why it's wrong here

    Default bucket encryption and CloudTrail's SSE-S3 encryption are fully compatible and do not conflict. When CloudTrail writes an object without an encryption header, S3 applies the bucket's default encryption automatically, so the log file is encrypted. The problem here is not a conflict between encryption mechanisms; it is that the bucket policy condition explicitly demands an encryption header that CloudTrail does not supply. Disabling default encryption would not fix the issue because the policy denial still occurs regardless of the bucket encryption setting.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.