Courseiva
Security and Compliance →mediumMultiple Select

SOA-C02 Security and Compliance Practice Question

Which TWO actions can a SysOps administrator take to secure an Amazon S3 bucket that contains sensitive data? (Choose TWO.)

⚠ Common exam trap

It's easy for candidates to confuse operational features like replication or MFA Delete with security controls that prevent unauthorized access or ensure encryption, leading them to select options that do not directly secure sensitive data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable default encryption using AWS KMS (SSE-KMS) on the bucket.

Enabling default encryption with SSE-KMS ensures that all objects uploaded to the S3 bucket are automatically encrypted at rest using AWS KMS-managed keys. This protects sensitive data even if the uploader forgets to specify encryption, meeting security and compliance requirements for data-at-rest protection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure a cross-origin resource sharing (CORS) policy.

    Why it's wrong here

    A CORS policy regulates which web origins are permitted to make cross-origin HTTP requests to a bucket from a browser. It does not authenticate users, prevent direct S3 API calls, or encrypt data at rest, and misconfiguring it can actually broaden exposure to web clients. Therefore, CORS is a browser access feature, not a bucket security control.

  • ✓

    Enable default encryption using AWS KMS (SSE-KMS) on the bucket.

    Why this is correct

    Enabling default encryption with SSE-KMS ensures that every object uploaded without an explicit encryption header is automatically encrypted at rest using a KMS-managed customer key. This provides envelope encryption and allows you to control key access through IAM policies, while CloudTrail records key usage for auditing. It directly addresses data-at-rest confidentiality, making it a necessary and effective security action.

  • ✗

    Enable cross-region replication for the bucket.

    Why it's wrong here

    Cross-region replication asynchronously copies objects to a destination bucket in another AWS Region, which is primarily used for disaster recovery, latency reduction, or regulatory data residency. It does not modify source bucket permissions, prevent unauthorized access, or enforce encryption at rest; the copied objects are simply new objects in the destination. Thus, replication supports durability and availability, not the security of the source bucket.

  • ✓

    Block all public access to the bucket using the S3 Block Public Access feature.

    Why this is correct

    S3 Block Public Access is a set of bucket- and account-level settings that override existing bucket policies, ACLs, and any other configurations that could grant public access. When enabled, even a deliberately permissive bucket policy cannot expose data to the internet. It is a preventive security control that directly mitigates the risk of unauthorized public data leakage.

  • ✗

    Enable MFA Delete on the bucket to require multi-factor authentication for delete operations.

    Why it's wrong here

    MFA Delete is a versioning-related feature that requires multi-factor authentication to permanently delete object versions or change the versioning state of a bucket. It is narrowly designed to prevent accidental or malicious destructive operations, not to restrict read access, block public exposure, or encrypt data. Therefore, it addresses deletion protection but does not secure the bucket in a general, comprehensive sense.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on SOA-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which TWO actions should a SysOps administrator take to secure an S3 bucket that stores sensitive data? (Choose two.)

hard
  • ✓ A.Enable S3 Block Public Access settings on the bucket.
  • B.Enable cross-origin resource sharing (CORS) on the bucket.
  • C.Enable S3 Versioning.
  • ✓ D.Enable S3 server access logging.
  • E.Enable S3 Transfer Acceleration.

Why A: Option A is correct because enabling S3 Block Public Access on the bucket applies the four block-public-access settings (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets) that prevent sensitive objects from ever being exposed through public ACLs or bucket policies. Option D is correct because S3 server access logging records detailed, request-level records (requester, bucket, key, operation, response status, source IP) to a target bucket, giving the audit trail needed to detect and investigate unauthorized access to sensitive data. Option B is not appropriate because CORS only controls which web origins may make cross-origin browser requests to the bucket; it is a browser-enforcement mechanism, not an access-control or data-protection control. Option C is not appropriate because S3 Versioning only preserves multiple object versions to aid recovery from overwrites or deletes; it does not restrict who can read the data. Option E is not appropriate because S3 Transfer Acceleration merely speeds up uploads/downloads via AWS edge locations and provides no security benefit.

Variation 2. Which TWO actions can be taken to secure an S3 bucket that contains sensitive data? (Choose two.)

medium
  • A.Enable versioning on the bucket
  • B.Add a bucket policy that allows only HTTPS requests
  • ✓ C.Enable default encryption for the bucket
  • D.Enable AWS CloudTrail for the bucket
  • ✓ E.Block all public access at the account level

Why C: Blocking all public access at the account level (Option E) prevents any public access to all buckets in the account, ensuring sensitive data is not exposed. Enabling default encryption (Option C) ensures that all objects uploaded to the bucket are encrypted at rest, protecting data even if the bucket or objects are compromised. Option A is incorrect because versioning protects against accidental deletion or overwrite, but does not secure data. Option B is incorrect; while a bucket policy that allows only HTTPS enforces encryption in transit, it is not the most direct or comprehensive security measure for sensitive data. Option D is incorrect because AWS CloudTrail logs API activity but does not directly secure the bucket.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.