Enable the proactive Control Tower S3 KMS-encryption control with CloudFormation hooks on all OUs
A company uses AWS Control Tower and AWS CloudFormation to manage its AWS accounts and to create AWS resources. The company requires all Amazon S3 buckets to be encrypted with AWS Key Management Service (AWS KMS) when the S3 buckets are created in a CloudFormation stack. Which solution will meet this requirement?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The requirement is preventative, enforced at creation time inside CloudFormation, which is exactly what Control Tower proactive controls with CloudFormation hooks do (B). Detective controls (C) evaluate after the resource exists and only generate findings, so they cannot prevent an unencrypted bucket from being created. Option A targets s3:PutObject rather than bucket creation, so it governs the data path and not the provisioning of the bucket, and option D relies on a permissions boundary, which does not apply to service API calls the way the requirement demands.
Every S3 bucket created through CloudFormation must be KMS-encrypted at creation time. Because the requirement applies to bucket creation within stacks, a detective control that only reports after the fact is insufficient, and an SCP cannot enforce a header on the PutObject data path. The correct approach is a multi-account Control Tower environment with proactive controls enabled on all organizational units backed by CloudFormation hooks, which block a stack operation before a bucket is created without the required KMS encryption.
Choosing an SCP that denies s3:PutObject unless the SSE-KMS header is present (A)—this governs object writes rather than the creation of the bucket, so a bucket can still be created unencrypted and the control does not satisfy the requirement. Enabling detective controls (C)—they identify noncompliance after the fact instead of preventing the noncompliant stack operation, so the bucket would still be created without encryption.
Community Discussion (10 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The requirement is that S3 buckets be KMS-encrypted when they are created in a CloudFormation stack, which is a preventative control evaluated at provisioning time. In a multi-account Control Tower environment, enabling proactive controls on all organizational units together with CloudFormation hooks causes the stack operation to be blocked when a bucket would be created without the required server-side encryption using an AWS KMS key, which is the control referenced as CT.S3.PR.10. This prevents the noncompliant resource from ever being created.Why the Other Options Are Wrong
A attaches an SCP that denies s3:PutObject when the request lacks the SSE-KMS header. That governs object-level writes into a bucket, not the creation of the bucket itself, so an unencrypted bucket can still be provisioned and the requirement is not met. C enables detective controls, which evaluate configuration after the resource exists and emit findings; they detect the problem but do not stop the stack from creating an unencrypted bucket. D combines a Config organizational rule that only checks whether a KMS key is enabled with a permissions boundary on a role, which does not govern provisioning-time enforcement for bucket creation. B is the correct choice.Community Comment Notes
Community voted B (97). Commenters keyed on the word 'proactive', noting that proactive controls block actions violating policy before they occur, so encryption is applied as the bucket is created. thanhnv142 pointed out that A's SCP only restricts PutObject rather than the creation action, and that detective controls in C only report after the fact.Official Reference
Related Analysis
Practice All DOP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full DOP-C02 Practice Test →