SOA-C02 Security and Compliance Practice Question
An organization requires that all Amazon S3 buckets be encrypted with AES-256 server-side encryption. A SysOps administrator needs to enforce this policy across the entire AWS account. Which action should be taken?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Apply an S3 bucket policy that denies s3:PutObject unless the request includes the x-amz-server-side-encryption header set to AES256.
A bucket policy that denies PutObject without the x-amz-server-side-encryption header set to AES256 will enforce encryption. Option A is wrong because default encryption does not prevent objects from being uploaded without encryption header. Option B is wrong because CloudTrail logs but does not enforce. Option C is wrong because S3 Inventory does not enforce.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable default encryption on all existing and future S3 buckets.
Why it's wrong here
S3 default encryption is a bucket-level fallback: it automatically encrypts objects only when the upload request omits a server-side encryption header. It is not an enforcement control because a client can explicitly include a different encryption header such as aws:kms, and existing objects already in the bucket will remain unencrypted after enabling the setting. Thus it cannot guarantee that every object stored in the bucket is both encrypted and specifically AES256.
- ✗
Use AWS CloudTrail to monitor uploads without encryption and alert the administrator.
Why it's wrong here
AWS CloudTrail is a detective audit service, not a preventive security control. It records data events such as s3:PutObject after the operation has already succeeded, and while the event may contain encryption-related request parameters, CloudTrail cannot block or influence the request being processed. An upload that sets no encryption header will still write an unencrypted object, and the administrator is merely alerted after the fact, possibly with no easy way to retroactively enforce compliance.
- ✗
Use S3 Inventory to list unencrypted objects and remediate them manually.
Why it's wrong here
S3 Inventory is a reporting feature that periodically produces a CSV/Parquet catalog of object metadata, including each object's encryption status. It is useful for identifying unencrypted objects after they have been uploaded and for tracking them, but it is fundamentally reactive: it requires a human or separate remediation process to fix noncompliant objects. Inventory does not sit in the request path and therefore has no ability to deny a new s3:PutObject that creates an unencrypted object.
- ✓
Apply an S3 bucket policy that denies s3:PutObject unless the request includes the x-amz-server-side-encryption header set to AES256.
Why this is correct
This bucket policy is the correct preventive control. By using a Deny statement with the s3:x-amz-server-side-encryption condition key and the StringNotEquals operator, S3 evaluates the policy before accepting any PUT and rejects the request unless the header is exactly AES256. This forces every upload—from CLI, SDKs, or other IAM principals—to explicitly request SSE-S3 encryption, and it overrides any default bucket encryption behavior because the policy blocks requests that do not meet the condition.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.