A cloud security engineer needs to enforce encryption for all objects uploaded to an Amazon S3 bucket. The team wants to ensure that any uploads without encryption headers are automatically denied. What is the correct approach to enforce this policy at the bucket level?