Courseiva
Security and Compliance →mediumMultiple Choice

SOA-C02 Security and Compliance Practice Question

An organization requires that all Amazon S3 buckets be encrypted at rest by default. A SysOps administrator needs to enforce this using AWS Config. Which AWS Config managed rule should be used?

⚠ Common exam trap

Many exam-takers confuse encryption in transit (SSL/TLS) with encryption at rest, leading them to select `s3-bucket-ssl-requests-only` instead of the correct rule for default encryption.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

s3-bucket-encryption-enabled

The AWS Config managed rule `s3-bucket-encryption-enabled` checks whether S3 buckets have default encryption enabled (SSE-S3, SSE-KMS, or SSE-C). This directly enforces the requirement that all buckets are encrypted at rest by default, as it evaluates each bucket's encryption configuration and flags non-compliant resources.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    s3-bucket-encryption-enabled

    Why this is correct

    The AWS Config managed rule s3-bucket-encryption-enabled evaluates whether an S3 bucket has default encryption enabled, which is satisfied by configuring either SSE-S3 or SSE-KMS. This ensures new objects written to the bucket are automatically encrypted at rest, directly meeting the organization's encryption requirement. Without this rule, a bucket could store plaintext objects, making it the correct choice.

  • ✗

    s3-bucket-ssl-requests-only

    Why it's wrong here

    s3-bucket-ssl-requests-only validates that bucket policies enforce the aws:SecureTransport condition, thereby requiring TLS/SSL for any client connection to the bucket. This rule governs encryption in transit—data moving between the client and S3—but does not inspect how the data is stored. A bucket can be SSL-only yet still contain unencrypted data at rest, so it does not satisfy the encryption-at-rest requirement.

  • ✗

    s3-bucket-public-read-prohibited

    Why it's wrong here

    s3-bucket-public-read-prohibited checks bucket policies and ACLs to ensure no public read access is granted to the bucket or its objects. This is an access-control measure designed to prevent unauthorized exposure, not a data-protection mechanism for stored content. A bucket can be completely private and still store unencrypted objects, so this rule is irrelevant to the encryption mandate.

  • ✗

    s3-bucket-logging-enabled

    Why it's wrong here

    s3-bucket-logging-enabled verifies that server access logging is enabled on the bucket, which records detailed request data for auditing and operational monitoring. While logging is a best practice for security visibility, it applies no cryptographic protection to the bucket's contents. Enabling logging does not affect whether objects are encrypted at rest, making this rule non-compliant with the stated policy.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.