AWS Certified Advanced Networking – Specialty (ANS-C01)Network Security, Compliance, and GovernanceEasy

A company is deploying a new application that uses Amazon S3 to store critical business data. To meet compliance requirements, all data must be encrypted at rest. The security team wants to ensure that the encryption is enabled by default for all new objects uploaded to S3 buckets, without requiring application changes or users to explicitly specify encryption headers. Which S3 bucket configuration would achieve this?

  1. AEnable S3 Versioning and Cross-Region Replication (CRR) for encryption.
  2. BEnable default encryption for the S3 bucket using SSE-S3.
  3. CConfigure an S3 bucket policy to deny uploads of unencrypted objects.
  4. DUse Server-Side Encryption with Customer-Provided Keys (SSE-C) for all uploads.
Show answer & explanation

Correct answer: B. Enable default encryption for the S3 bucket using SSE-S3.

Enabling default encryption for an S3 bucket with SSE-S3 (Server-Side Encryption with Amazon S3-Managed Keys) ensures that all new objects uploaded to that bucket are automatically encrypted at rest. This requires no changes to the application or explicit encryption headers from users, directly meeting the requirements.

Why the other options are wrong

  • A. S3 Versioning and CRR are for data durability and replication, not for enforcing default encryption at rest for initial uploads.
  • C. While a bucket policy can deny unencrypted uploads, it still requires the client to explicitly request encryption. Default encryption is a simpler solution to ensure all objects are encrypted without client-side intervention.
  • D. SSE-C requires the client to provide encryption keys with each upload, which goes against the requirement of 'without requiring application changes or users to explicitly specify encryption headers'.

S3 Default Encryption (SSE-S3)

A configuration on an Amazon S3 bucket that automatically encrypts all new objects uploaded to it using Server-Side Encryption with S3-managed keys (SSE-S3).

  • Encrypts data at rest automatically upon upload.
  • Uses S3-managed encryption keys (SSE-S3).
  • Requires no application changes or explicit encryption headers from users.
  • Ensures all new objects meet a base level of encryption compliance.

Memory trick: Default S3 encryption means every new object is locked.

More Network Security, Compliance, and Governance questions