Enable the proactive Control Tower S3 KMS-encryption control with CloudFormation hooks on all OUs

Answer Correct answer: B — enable proactive Control Tower controls with CloudFormation hooks on all OUs to block creation of S3 buckets lacking KMS encryption.

A company uses AWS Control Tower and AWS CloudFormation to manage its AWS accounts and to create AWS resources. The company requires all Amazon S3 buckets to be encrypted with AWS Key Management Service (AWS KMS) when the S3 buckets are created in a CloudFormation stack. Which solution will meet this requirement?

  1. Use AWS Organizations. Attach an SCP that denies the s3:PutObject permission if the request does not include an x-amz-server-side-encryption header that requests server-side encryption with AWS KMS keys (SSE-KMS).
  2. Use AWS Control Tower with a multi-account environment. Configure and enable proactive AWS Control Tower controls on all OUs with CloudFormation hooks. Correct Answer
  3. Use AWS Control Tower with a multi-account environment. Configure and enable detective AWS Control Tower controls on all OUs with CloudFormation hooks.
  4. Use AWS Organizations. Create an AWS Config organizational rule to check whether a KMS encryption key is enabled for all S3 buckets. Deploy the rule. Create and apply an SCP to prevent users from stopping and deleting AWS Config across all AWS accounts,

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The requirement is preventative, enforced at creation time inside CloudFormation, which is exactly what Control Tower proactive controls with CloudFormation hooks do (B). Detective controls (C) evaluate after the resource exists and only generate findings, so they cannot prevent an unencrypted bucket from being created. Option A targets s3:PutObject rather than bucket creation, so it governs the data path and not the provisioning of the bucket, and option D relies on a permissions boundary, which does not apply to service API calls the way the requirement demands.

Every S3 bucket created through CloudFormation must be KMS-encrypted at creation time. Because the requirement applies to bucket creation within stacks, a detective control that only reports after the fact is insufficient, and an SCP cannot enforce a header on the PutObject data path. The correct approach is a multi-account Control Tower environment with proactive controls enabled on all organizational units backed by CloudFormation hooks, which block a stack operation before a bucket is created without the required KMS encryption.

Choosing an SCP that denies s3:PutObject unless the SSE-KMS header is present (A)—this governs object writes rather than the creation of the bucket, so a bucket can still be created unencrypted and the control does not satisfy the requirement. Enabling detective controls (C)—they identify noncompliance after the fact instead of preventing the noncompliant stack operation, so the bucket would still be created without encryption.

Community Discussion (10 comments)

Ramdi1 👍 5 Selected: B
Proactive controls: Proactive controls are preventative measures that block actions violating defined policies before they occur. This ensures encryption gets applied automatically during S3 bucket creation within CloudFormation stacks. CloudFormation hooks: Hooks enable Control Tower to intercept and enforce policies on CloudFormation stack operations, making it ideal for enforcing encryption during resource creation. Multi-account environment: Since the requirement applies across all accounts, Control Tower's multi-account capabilities ensure consistent policy enforcement throughout the organization.
thanhnv142 👍 5 Selected: B
B is correct: <AWS Control Tower> means we need to use the proactive control A: SCP s3:PutObject permission only deny action related to put object to S3, not when creating it B: Detective controls used only for monitoring C: correct D: This option can achive the goal of the question. However, it is way more complicated than B.
jamesf 👍 3 Selected: B
keywords: proactive
Gomer 👍 4 Selected: B
Here's the Control Tower proactive control: "[CT.S3.PR.10] Require an Amazon S3 bucket to have server-side encryption configured using an AWS KMS key" https://docs.aws.amazon.com/controltower/latest/controlreference/s3-rules.html#ct-s3-pr-10-description
Venki_dev 👍 2 Selected: B
Clearly answer is B , here is article that explains the same. https://aws.amazon.com/blogs/mt/how-aws-control-tower-users-can-proactively-verify-compliance-in-aws-cloudformation-stacks/ Answer D with config rule also fits the bill (if no control tower), but since we have Control tower managing the accounts already its better to make use of the features that Control tower leverages
dkp 👍 3 Selected: B
Answer B
fdoxxx 👍 3 Selected: B
B is better than D...
ogerber 👍 3 Selected: B
B, 100%
fdoxxx 👍 1 Selected: D
D provides a solution that leverages AWS Organizations and AWS Config to enforce the requirement for AWS KMS encryption on all S3 buckets created through CloudFormation: AWS Config Organizational Rule: Create an AWS Config organizational rule to check whether a KMS encryption key is enabled for all S3 buckets. This rule helps ensure that the encryption requirement is enforced. Options A, B, and C do not directly address the requirement for AWS KMS encryption on S3 buckets created through CloudFormation: Option A mentions using an SCP but focuses on denying s3:PutObject without the required encryption header. However, this approach doesn't ensure that the encryption is enforced through AWS KMS. Options B and C mention using AWS Control Tower with proactive or detective controls, but they don't specifically address the encryption requirement for S3 buckets.
Chelseajcole 👍 1
Maybe D

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The requirement is that S3 buckets be KMS-encrypted when they are created in a CloudFormation stack, which is a preventative control evaluated at provisioning time. In a multi-account Control Tower environment, enabling proactive controls on all organizational units together with CloudFormation hooks causes the stack operation to be blocked when a bucket would be created without the required server-side encryption using an AWS KMS key, which is the control referenced as CT.S3.PR.10. This prevents the noncompliant resource from ever being created.

Why the Other Options Are Wrong

A attaches an SCP that denies s3:PutObject when the request lacks the SSE-KMS header. That governs object-level writes into a bucket, not the creation of the bucket itself, so an unencrypted bucket can still be provisioned and the requirement is not met. C enables detective controls, which evaluate configuration after the resource exists and emit findings; they detect the problem but do not stop the stack from creating an unencrypted bucket. D combines a Config organizational rule that only checks whether a KMS key is enabled with a permissions boundary on a role, which does not govern provisioning-time enforcement for bucket creation. B is the correct choice.

Community Comment Notes

Community voted B (97). Commenters keyed on the word 'proactive', noting that proactive controls block actions violating policy before they occur, so encryption is applied as the bucket is created. thanhnv142 pointed out that A's SCP only restricts PutObject rather than the creation action, and that detective controls in C only report after the fact.

Official Reference

Related Analysis

Practice All DOP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full DOP-C02 Practice Test →

← Back to DOP-C02 Study Guide