SOA-C02 Security and Compliance Practice Question
An organization requires that all Amazon S3 buckets be encrypted at rest by default. A SysOps administrator needs to enforce this using AWS Config. Which AWS Config managed rule should be used?
⚠ Common exam trap
Many exam-takers confuse encryption in transit (SSL/TLS) with encryption at rest, leading them to select `s3-bucket-ssl-requests-only` instead of the correct rule for default encryption.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
s3-bucket-encryption-enabled
The AWS Config managed rule `s3-bucket-encryption-enabled` checks whether S3 buckets have default encryption enabled (SSE-S3, SSE-KMS, or SSE-C). This directly enforces the requirement that all buckets are encrypted at rest by default, as it evaluates each bucket's encryption configuration and flags non-compliant resources.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
s3-bucket-encryption-enabled
Why this is correct
The AWS Config managed rule s3-bucket-encryption-enabled evaluates whether an S3 bucket has default encryption enabled, which is satisfied by configuring either SSE-S3 or SSE-KMS. This ensures new objects written to the bucket are automatically encrypted at rest, directly meeting the organization's encryption requirement. Without this rule, a bucket could store plaintext objects, making it the correct choice.
- ✗
s3-bucket-ssl-requests-only
Why it's wrong here
s3-bucket-ssl-requests-only validates that bucket policies enforce the aws:SecureTransport condition, thereby requiring TLS/SSL for any client connection to the bucket. This rule governs encryption in transit—data moving between the client and S3—but does not inspect how the data is stored. A bucket can be SSL-only yet still contain unencrypted data at rest, so it does not satisfy the encryption-at-rest requirement.
- ✗
s3-bucket-public-read-prohibited
Why it's wrong here
s3-bucket-public-read-prohibited checks bucket policies and ACLs to ensure no public read access is granted to the bucket or its objects. This is an access-control measure designed to prevent unauthorized exposure, not a data-protection mechanism for stored content. A bucket can be completely private and still store unencrypted objects, so this rule is irrelevant to the encryption mandate.
- ✗
s3-bucket-logging-enabled
Why it's wrong here
s3-bucket-logging-enabled verifies that server access logging is enabled on the bucket, which records detailed request data for auditing and operational monitoring. While logging is a best practice for security visibility, it applies no cryptographic protection to the bucket's contents. Enabling logging does not affect whether objects are encrypted at rest, making this rule non-compliant with the stated policy.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.