nerdexam
Amazon

DVA-C02 · Question #13

A company has an Amazon S3 bucket that contains sensitive data. The data must be encrypted in transit and at rest. The company encrypts the data in the S3 bucket by using an AWS Key Management…

The correct answer is A. Define a resource-based policy on the S3 bucket to deny access when a request meets the. https://aws.amazon.com/premiumsupport/knowledge-center/s3-bucket-policy-for-config-rule/

Submitted by yuriko_h· Mar 5, 2026Security

Question

A company has an Amazon S3 bucket that contains sensitive data. The data must be encrypted in transit and at rest. The company encrypts the data in the S3 bucket by using an AWS Key Management Service (AWS KMS) key. A developer needs to grant several other AWS accounts the permission to use the S3 GetObject operation to retrieve the data from the S3 bucket. How can the developer enforce that all requests to retrieve the data provide encryption in transit?

Options

  • ADefine a resource-based policy on the S3 bucket to deny access when a request meets the
  • BDefine a resource-based policy on the S3 bucket to allow access when a request meets the
  • CDefine a role-based policy on the other accounts' roles to deny access when a request meets the
  • DDefine a resource-based policy on the KMS key to deny access when a request meets the

How the community answered

(29 responses)
  • A
    62% (18)
  • B
    24% (7)
  • C
    3% (1)
  • D
    10% (3)

Explanation

https://aws.amazon.com/premiumsupport/knowledge-center/s3-bucket-policy-for-config-rule/

Community Discussion

No community discussion yet for this question.

Full DVA-C02 Practice