Practice SCS-C03 Data Protection questions with full explanations on every answer.
Start practicing
Data Protection — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
A company stores sensitive PII in RDS MySQL databases. The security team wants to ensure that data is encrypted at rest and that the encryption keys are rotated annually. Which TWO actions fulfill these requirements?
2A company needs to share an encrypted EBS volume snapshot with a partner's AWS account. The snapshot is encrypted with a customer-managed KMS key. What must the company do to enable this sharing?
3An organization wants to rotate their KMS customer-managed keys every 90 days. What is the most effective way to implement this?
4An application in Account A needs to decrypt S3 objects in Account B using a KMS key in Account B. What is the minimal configuration required?
5Which service should be used to protect sensitive data from being exfiltrated via API calls to unauthorized services?
6A company is migrating a legacy database to Amazon RDS for MySQL and must ensure the data is protected according to strict compliance standards. The security team requires that the data at rest is encrypted and that the encryption cannot be disabled after the instance is created. Which TWO statements accurately describe RDS encryption behavior?
7An organization is using AWS Secrets Manager to store database credentials. The security policy requires that these credentials be rotated every 30 days. The database is hosted on Amazon RDS. What is the most secure and automated way to implement this requirement?
8A security architect is designing a cross-account data sharing solution. Account A owns a KMS Customer Managed Key (CMK) that must be used by an IAM role in Account B to decrypt S3 objects. Which TWO steps are required to enable this cross-account access?
9A company wants to ensure that all new Amazon EBS volumes created in their account are automatically encrypted, regardless of whether the developer specifies encryption during the volume creation process. Which AWS feature should be used?
10A security engineer needs to identify and protect Personally Identifiable Information (PII) stored in thousands of S3 buckets across multiple AWS accounts. The solution must provide a centralized dashboard and use machine learning to classify data. Which service is best suited for this task?
11A company is implementing a new internal web application and needs to use SSL/TLS certificates. Due to regulatory requirements, the certificates must be issued by a private Certificate Authority (CA) managed by the company, rather than a public CA. Which AWS service should be used to meet this requirement?
12A financial institution requires that all data stored in S3 buckets be immutable for five years to comply with regulatory requirements. They also need to ensure that even the root user cannot delete the data or shorten the retention period. Which configuration should the security engineer implement?
13An organization is using Amazon Macie to protect sensitive data in S3. They want to ensure they are alerted to the presence of PII across all buckets. Which TWO actions are required to configure Macie to identify sensitive data effectively?
14Refer to the exhibit. A developer is attempting to upload an object to 'my-secure-bucket' using the AWS CLI but receives an 'Access Denied' error. The developer's command was: 'aws s3 cp file.txt s3://my-secure-bucket/file.txt'. What is the most likely cause of the failure?
15A company is setting up a private Public Key Infrastructure (PKI) on AWS to issue certificates for internal microservices. They need to ensure that the private keys of the CA are protected by a FIPS 140-2 Level 3 validated Hardware Security Module (HSM). Which service should they use?
The Data Protection domain covers the key concepts tested in this area of the SCS-C03 exam blueprint published by Amazon Web Services. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all SCS-C03 domains — no account required.
The Courseiva SCS-C03 question bank contains 15 questions in the Data Protection domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Data Protection domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included