A company must guarantee that every object uploaded to an S3 bucket is stored encrypted. Which of the following will enforce encryption for uploads? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: Enable Amazon S3 default encryption so objects are encrypted at storage time., Create an S3 bucket policy that rejects any upload requests that do not provide encryption..
Why this is the answer
Enabling Amazon S3 default encryption ensures that all new objects uploaded to the bucket are automatically encrypted at rest, even if the upload request does not specify encryption. This is a straightforward and effective way to enforce encryption. Creating an S3 bucket policy that rejects upload requests without encryption (e.g., without the x-amz-server-side-encryption header) is another robust method. This policy explicitly denies uploads that do not meet the encryption requirement, preventing unencrypted objects from ever being stored. AWS Shield is a DDoS protection service and does not enforce S3 object encryption. Object ACLs control access permissions, not encryption requirements. Amazon Inspector is a security assessment service that scans for vulnerabilities, but it does not prevent or enforce encryption during the upload process.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed