Courseiva
Security and Compliance →hardMultiple Select

SOA-C02 Security and Compliance Practice Question

Which TWO actions should a SysOps administrator take to secure an S3 bucket that stores sensitive data? (Choose two.)

⚠ Common exam trap

SOA-C02 often tests the misconception that features like Versioning or Transfer Acceleration improve security, when in fact Block Public Access and access logging are the correct security-focused controls.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable S3 Block Public Access settings on the bucket.

Option A is correct because enabling S3 Block Public Access on the bucket applies the four block-public-access settings (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets) that prevent sensitive objects from ever being exposed through public ACLs or bucket policies. Option D is correct because S3 server access logging records detailed, request-level records (requester, bucket, key, operation, response status, source IP) to a target bucket, giving the audit trail needed to detect and investigate unauthorized access to sensitive data. Option B is not appropriate because CORS only controls which web origins may make cross-origin browser requests to the bucket; it is a browser-enforcement mechanism, not an access-control or data-protection control. Option C is not appropriate because S3 Versioning only preserves multiple object versions to aid recovery from overwrites or deletes; it does not restrict who can read the data. Option E is not appropriate because S3 Transfer Acceleration merely speeds up uploads/downloads via AWS edge locations and provides no security benefit.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable S3 Block Public Access settings on the bucket.

    Why this is correct

    This is a bucket-level and account-level security control that, when applied, overrides any bucket policies or object ACLs that would grant public read/write access, effectively preventing the bucket and its objects from being accessible to the anonymous internet. For a scenario requiring data to be kept private, blocking public access is the direct and definitive remedy, and it also prevents future accidental public exposure through misconfigured policies or ACLs.

  • ✗

    Enable cross-origin resource sharing (CORS) on the bucket.

    Why it's wrong here

    CORS configures how web browsers are allowed to load resources from a different origin. It's about relaxing the same-origin policy for legitimate cross-domain requests, not about restricting access or protecting data from unauthorized users. CORS does not affect whether objects are publicly readable; it only governs HTTP header behavior for browser-based clients.

  • ✗

    Enable S3 Versioning.

    Why it's wrong here

    Versioning keeps multiple variants of an object, letting you recover from accidental deletion or overwrites, but it does not restrict who can read or write objects. It actually adds storage and can complicate lifecycle management; it doesn't block public access or enforce authentication/authorization.

  • ✓

    Enable S3 server access logging.

    Why this is correct

    This records detailed records of all requests made to the bucket—requester, IP, action, response status—into a designated logging bucket. While it doesn't prevent unauthorized access, it provides a forensic audit trail that allows you to detect probing, verify that previous public exposure occurred, and support incident investigation after a breach.

  • ✗

    Enable S3 Transfer Acceleration.

    Why it's wrong here

    This feature uses a global network of edge locations to speed up uploads over long distances by transferring data from the edge to S3 over optimized network paths. It has no impact on access control or data protection; it's purely a performance booster for high-latency or high-bandwidth transfers, and can actually incur additional costs.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.