SOA-C02 Security and Compliance Practice Question
Exhibit
Refer to the exhibit.
CloudTrail log entry:
{
"eventVersion": "1.08",
"userIdentity": {
"type": "IAMUser",
"arn": "arn:aws:iam::123456789012:user/john.doe",
"accountId": "123456789012",
"userName": "john.doe"
},
"eventTime": "2023-10-01T12:34:56Z",
"eventSource": "s3.amazonaws.com",
"eventName": "PutObject",
"awsRegion": "us-east-1",
"sourceIPAddress": "192.0.2.1",
"userAgent": "[S3Console]",
"requestParameters": {
"bucketName": "my-secure-bucket",
"key": "confidential.pdf",
"x-amz-server-side-encryption": "AES256"
},
"responseElements": {
"x-amz-server-side-encryption": "AES256"
}
}Refer to the exhibit. The security team wants to ensure that all objects uploaded to the S3 bucket 'my-secure-bucket' are encrypted at rest. Based on the CloudTrail log entry, what can be concluded about the object 'confidential.pdf'?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The object is encrypted with SSE-S3
The CloudTrail log entry shows that the object 'confidential.pdf' was uploaded with the 'x-amz-server-side-encryption' header set to 'AES256'. This header indicates that server-side encryption with Amazon S3-managed keys (SSE-S3) was requested. The response also confirms that encryption was applied. Therefore, the object is encrypted with SSE-S3, making option C correct. Option A is incorrect because the log does not mention KMS key details. Option B is incorrect because the object is encrypted. Option D is incorrect because the encryption header was provided.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The object is encrypted with AWS KMS
Why it's wrong here
The SSE algorithm recorded for this object is AES256, not aws:kms. SSE-KMS would be indicated by an x-amz-server-side-encryption header value of aws:kms followed by a call to AWS KMS and the presence of a KMS key identifier, such as an arn:aws:kms:... key ARN. Because the log shows AES256, the object is encrypted with SSE-S3, which uses Amazon-managed keys rather than customer-managed KMS keys.
- ✗
The object is not encrypted
Why it's wrong here
This is incorrect because the log entry explicitly shows that server-side encryption was applied to the object at rest. The x-amz-server-side-encryption header has a value of AES256, which is a definitive indication that the object is encrypted. Even if the bucket's default encryption applied the setting automatically, the effective encryption is still active, so the object is not unencrypted.
- ✓
The object is encrypted with SSE-S3
Why this is correct
The header value AES256 is the standard indicator for SSE-S3, where Amazon S3 manages the encryption keys entirely on your behalf. SSE-S3 uses the AES-256-GCM block cipher to encrypt objects at rest and provides automatic, transparent encryption with no additional cost or key management burden. The logged value matches this mode exactly, confirming that the object is encrypted with SSE-S3.
- ✗
The object was uploaded without an encryption header
Why it's wrong here
The log shows that the x-amz-server-side-encryption header was present in the request and carried the value AES256. If the object had been uploaded without an encryption header, the log would not contain an SSE-specific header or would show a null value for that field. The presence of the AES256 value proves the upload included an encryption specification, either explicitly or through the bucket's default encryption policy.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.