Courseiva
Security and Compliance →hardMultiple Choice

SOA-C02 Security and Compliance Practice Question

Exhibit

Refer to the exhibit.

CloudTrail log entry:
{
  "eventVersion": "1.08",
  "userIdentity": {
    "type": "IAMUser",
    "arn": "arn:aws:iam::123456789012:user/john.doe",
    "accountId": "123456789012",
    "userName": "john.doe"
  },
  "eventTime": "2023-10-01T12:34:56Z",
  "eventSource": "s3.amazonaws.com",
  "eventName": "PutObject",
  "awsRegion": "us-east-1",
  "sourceIPAddress": "192.0.2.1",
  "userAgent": "[S3Console]",
  "requestParameters": {
    "bucketName": "my-secure-bucket",
    "key": "confidential.pdf",
    "x-amz-server-side-encryption": "AES256"
  },
  "responseElements": {
    "x-amz-server-side-encryption": "AES256"
  }
}

Refer to the exhibit. The security team wants to ensure that all objects uploaded to the S3 bucket 'my-secure-bucket' are encrypted at rest. Based on the CloudTrail log entry, what can be concluded about the object 'confidential.pdf'?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The object is encrypted with SSE-S3

The CloudTrail log entry shows that the object 'confidential.pdf' was uploaded with the 'x-amz-server-side-encryption' header set to 'AES256'. This header indicates that server-side encryption with Amazon S3-managed keys (SSE-S3) was requested. The response also confirms that encryption was applied. Therefore, the object is encrypted with SSE-S3, making option C correct. Option A is incorrect because the log does not mention KMS key details. Option B is incorrect because the object is encrypted. Option D is incorrect because the encryption header was provided.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The object is encrypted with AWS KMS

    Why it's wrong here

    The SSE algorithm recorded for this object is AES256, not aws:kms. SSE-KMS would be indicated by an x-amz-server-side-encryption header value of aws:kms followed by a call to AWS KMS and the presence of a KMS key identifier, such as an arn:aws:kms:... key ARN. Because the log shows AES256, the object is encrypted with SSE-S3, which uses Amazon-managed keys rather than customer-managed KMS keys.

  • ✗

    The object is not encrypted

    Why it's wrong here

    This is incorrect because the log entry explicitly shows that server-side encryption was applied to the object at rest. The x-amz-server-side-encryption header has a value of AES256, which is a definitive indication that the object is encrypted. Even if the bucket's default encryption applied the setting automatically, the effective encryption is still active, so the object is not unencrypted.

  • ✓

    The object is encrypted with SSE-S3

    Why this is correct

    The header value AES256 is the standard indicator for SSE-S3, where Amazon S3 manages the encryption keys entirely on your behalf. SSE-S3 uses the AES-256-GCM block cipher to encrypt objects at rest and provides automatic, transparent encryption with no additional cost or key management burden. The logged value matches this mode exactly, confirming that the object is encrypted with SSE-S3.

  • ✗

    The object was uploaded without an encryption header

    Why it's wrong here

    The log shows that the x-amz-server-side-encryption header was present in the request and carried the value AES256. If the object had been uploaded without an encryption header, the log would not contain an SSE-specific header or would show a null value for that field. The presence of the AES256 value proves the upload included an encryption specification, either explicitly or through the bucket's default encryption policy.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.