AWS Certified SysOps Administrator – AssociateSecurity and ComplianceMedium

A global enterprise needs to ensure that all data stored in Amazon S3 buckets across all its AWS accounts is encrypted at rest using server-side encryption with KMS keys. The security team wants to enforce this policy universally and prevent any account from deploying S3 buckets without this encryption. What is the MOST effective way to achieve this across all accounts managed by AWS Organizations?

  1. ACreate an AWS Config rule to detect non-compliant S3 buckets and remediate them.
  2. BConfigure S3 bucket policies on each new bucket to enforce server-side encryption with KMS.
  3. CDevelop a Lambda function triggered by CloudTrail events to check new S3 buckets for KMS encryption and delete non-compliant ones.
  4. DImplement a Service Control Policy (SCP) in AWS Organizations to deny the `s3:PutObject` action unless `x-amz-server-side-encryption-aws-kms-key-id` is specified.
Show answer & explanation

Correct answer: D. Implement a Service Control Policy (SCP) in AWS Organizations to deny the `s3:PutObject` action unless `x-amz-server-side-encryption-aws-kms-key-id` is specified.

Service Control Policies (SCPs) are ideal for enforcing mandatory guardrails across all accounts in an AWS Organization. By denying the PutObject action unless KMS encryption is specified, you prevent the creation of unencrypted objects at the organizational level.

Why the other options are wrong

  • A. AWS Config rules detect non-compliance but do not prevent it at the time of creation across multiple accounts without additional remediation actions, which might not be immediate.
  • B. This requires manual configuration or automation per bucket, which is not scalable or universally enforceable across all accounts.
  • C. This is a reactive approach that allows non-compliant resources to be created first, then deleted, which is less ideal than preventing creation in the first place, and it adds operational overhead.

Service Control Policies (SCPs)

SCPs are a type of organization policy that you can use to manage permissions in your organization. They offer central control over the maximum available permissions for all accounts in an organization.

  • Apply to all IAM users and roles in affected accounts.
  • Do not grant permissions directly; they filter permissions.
  • Can be used to deny specific actions or resources.
  • Preventive security control.

Memory trick: SCPs Secure Cloud Policies.

More Security and Compliance questions