AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question

A company stores sensitive financial reports in an Amazon S3 bucket. Compliance requires that every new object be encrypted at rest with a specific customer managed AWS KMS key. Any upload that does not use that key must be rejected immediately without manual review. As the CloudOps engineer, which approach meets the requirement while introducing the least operational overhead?

  • Create a bucket policy that denies s3:PutObject unless the request includes "s3:x-amz-server-side-encryption" set to "aws:kms" and "s3:x-amz-server-side-encryption-aws-kms-key-id" that matches the CMK ARN.

  • Enable default bucket encryption using SSE-KMS with the required CMK so S3 automatically encrypts all objects.

  • Turn on Amazon S3 Block Public Access for the bucket to ensure only encrypted uploads are accepted.

  • Deploy the AWS Config rule "s3-bucket-server-side-encryption-enabled" with automatic remediation to enforce SSE-KMS on the bucket.

AWS Certified CloudOps Engineer Associate SOA-C03
Security and Compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot