AWS Certified SysOps Administrator – AssociateDeployment, Provisioning, and AutomationMedium
A compliance team requires that all data stored in Amazon S3 buckets is automatically encrypted at rest using a customer-managed key (CMK) from AWS Key Management Service (KMS). This encryption policy must be enforced for all new and existing objects in specific buckets, and any attempt to upload unencrypted objects or objects encrypted with a different key should be rejected. Which S3 feature should be configured?
- AS3 Object Lock
- BS3 Lifecycle Policy
- CS3 Default Encryption
- DS3 Bucket Policy
Show answer & explanationAnswer & explanation
Correct answer: C. S3 Default Encryption
S3 Default Encryption allows you to enforce encryption for all new objects uploaded to a bucket, using either S3-managed keys (SSE-S3) or KMS keys (SSE-KMS). While a Bucket Policy can enforce this, Default Encryption simplifies the configuration and serves as the primary mechanism for setting a mandatory encryption standard for new objects.
Why the other options are wrong
- A. S3 Object Lock prevents objects from being deleted or overwritten for a fixed amount of time or indefinitely, not for enforcing encryption.
- B. S3 Lifecycle Policies manage object transitions and expirations, not encryption at upload time.
- D. An S3 Bucket Policy can *enforce* encryption by denying uploads that don't meet criteria, but S3 Default Encryption is the feature that *sets* the encryption by default for new objects and is simpler for this primary requirement.
S3 Default Encryption
A setting on an S3 bucket that automatically encrypts all new objects uploaded to that bucket, using either S3-managed encryption (SSE-S3) or AWS KMS encryption (SSE-KMS).
- Applies to all new objects uploaded to the bucket.
- Can use SSE-S3 or SSE-KMS.
- Simplifies compliance by enforcing encryption at rest.
Memory trick: Default Encryption defends data automatically.