AWS Certified SysOps Administrator – AssociateDeployment, Provisioning, and AutomationMedium
A company requires that all data stored in Amazon S3 buckets is automatically encrypted at rest. They want to enforce this rule across all new and existing buckets without requiring users to manually specify encryption settings during bucket creation or object upload. What is the most effective and compliant way to achieve this?
- AEnable default encryption for the S3 bucket using AES-256 or KMS.
- BImplement AWS Config rules to monitor for unencrypted S3 buckets and remediate them.
- CUse AWS KMS to encrypt objects before uploading them to S3.
- DApply an S3 bucket policy that denies `s3:PutObject` requests if the `x-amz-server-side-encryption` header is not present.
Show answer & explanationAnswer & explanation
Correct answer: A. Enable default encryption for the S3 bucket using AES-256 or KMS.
Enabling default encryption for an S3 bucket is the simplest and most effective way to ensure all new and existing objects are encrypted at rest. Once configured, all objects uploaded to the bucket are automatically encrypted using the specified encryption type (SSE-S3 or SSE-KMS) without requiring any action from the uploader.
Why the other options are wrong
- B. AWS Config rules can *monitor* for non-compliant buckets, but they don't *prevent* unencrypted uploads or automatically *enable* default encryption for new buckets. Remediation would be a separate step.
- C. Encrypting objects with KMS client-side before uploading requires manual action from users or application changes, which the requirement explicitly seeks to avoid.
- D. While a bucket policy can enforce encryption, enabling default encryption is a simpler and more direct way to achieve automatic encryption without denying uploads.
S3 Default Encryption
Amazon S3 Default Encryption allows you to configure an S3 bucket to automatically encrypt new objects when they are uploaded, ensuring all data at rest in the bucket is encrypted.
- Applies to all new objects uploaded to the bucket.
- Supports SSE-S3 (AES-256) or SSE-KMS.
- Eliminates the need for users to specify encryption headers.
Memory trick: Default Encryption makes S3 *definitely sure* all data is locked up.