AIF-C01 Practice Question: Security, Compliance, and Governance for AI Solutions
A healthcare company is building an AI application on AWS that processes patient records. The security team must ensure that data stored in Amazon S3 is encrypted at rest using a key that the company manages and can rotate independently. Which AWS service should they use to meet these requirements?
⚠ Common exam trap
The trap here is assuming that any KMS key provides independent rotation control, when only customer managed keys offer that level of management.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Key Management Service (AWS KMS) customer managed key
AWS KMS customer managed keys allow the company to create, manage, and rotate encryption keys independently. When used with S3 server-side encryption (SSE-KMS), the company retains control over the key lifecycle and access policies, directly meeting the requirement for company-managed encryption keys for patient records.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS KMS AWS managed key
Why it's wrong here
AWS managed keys are created and managed by AWS on the customer's behalf. The customer cannot rotate these keys independently or change their key policies. While they provide encryption at rest, they do not satisfy the requirement for a company-managed key with independent rotation control.
- ✗
AWS Secrets Manager
Why it's wrong here
AWS Secrets Manager is designed to store and rotate secrets such as database credentials and API keys. It does not provide encryption keys for S3 data at rest. Using it for S3 encryption is not its purpose and would not satisfy the encryption requirement.
- ✗
Amazon S3 default encryption with Amazon S3 managed keys (SSE-S3)
Why it's wrong here
SSE-S3 uses keys fully managed by Amazon S3. The customer has no control over key rotation or access policies. This does not meet the requirement for a company-managed key, as the keys are not owned or rotatable by the company.
- ✓
AWS Key Management Service (AWS KMS) customer managed key
Why this is correct
AWS KMS customer managed keys give the company full control over key creation, rotation, and access policies. They can enable automatic rotation and define granular permissions. This meets the requirement for a company-managed key that can be rotated independently, and it integrates with S3 server-side encryption to protect data at rest.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This AIF-C01 question is part of Courseiva's 862-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This AIF-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AIF-C01 exam.