A company is implementing a new policy that requires all S3 buckets to be encrypted at rest. They want to ensure that if a user attempts to upload an unencrypted object to any S3 bucket, the upload fails. Additionally, all existing unencrypted objects must be encrypted. Which combination of S3 features will provide the most comprehensive solution without requiring changes to existing application code?
- AUse AWS Config rules to detect unencrypted objects and trigger a Lambda function to encrypt them.
- BConfigure S3 Block Public Access at the account level and enable default encryption with SSE-S3.
- CImplement an S3 bucket policy that explicitly denies `s3:PutObject` if `s3:x-amz-server-side-encryption` header is not present, and enable S3 Inventory with a Lambda function for existing objects.
- DEnable default encryption for all S3 buckets with SSE-KMS and use S3 Batch Operations to encrypt existing objects.
Show answer & explanationAnswer & explanation
Correct answer: D. Enable default encryption for all S3 buckets with SSE-KMS and use S3 Batch Operations to encrypt existing objects.
Enabling default encryption with SSE-KMS for all buckets ensures that all *new* objects are automatically encrypted upon upload without requiring client-side headers. S3 Batch Operations can then be used to efficiently encrypt all *existing* unencrypted objects in the buckets. This provides both preventative control for new objects and remediation for existing ones, without application code changes.
Why the other options are wrong
- A. AWS Config is reactive; it detects issues after they occur. While a Lambda can encrypt, this doesn't *prevent* unencrypted uploads and is less direct than default encryption for new objects. Batch Operations is better for mass encryption of existing objects.
- B. S3 Block Public Access prevents public access, not encryption enforcement. Default encryption with SSE-S3 is a good start but often SSE-KMS is preferred for key management and it doesn't address existing objects.
- C. An S3 bucket policy can deny unencrypted uploads, but it requires the `s3:x-amz-server-side-encryption` header to be present, which might require application changes. S3 Inventory with Lambda for existing objects is a reactive/remediation approach, but Batch Operations is more direct.
S3 Default Encryption & Batch Operations
S3 Default Encryption automatically encrypts new objects. S3 Batch Operations allow large-scale operations (like encryption) on existing objects.
- Default encryption prevents unencrypted uploads.
- SSE-KMS offers managed key control.
- Batch Operations for re-encrypting existing objects.
- Comprehensive solution without application code changes.
Memory trick: Default encryption secures new, Batch Ops re-encrypts old.