Courseiva

AIF-C01 Practice Question: Security, Compliance, and Governance for AI Solutions

A healthcare company is building an AI application on AWS that processes patient records. The security team must ensure that data stored in Amazon S3 is encrypted at rest using a key that the company manages and can rotate independently. Which AWS service should they use to meet these requirements?

⚠ Common exam trap

The trap here is assuming that any KMS key provides independent rotation control, when only customer managed keys offer that level of management.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Key Management Service (AWS KMS) customer managed key

AWS KMS customer managed keys allow the company to create, manage, and rotate encryption keys independently. When used with S3 server-side encryption (SSE-KMS), the company retains control over the key lifecycle and access policies, directly meeting the requirement for company-managed encryption keys for patient records.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS KMS AWS managed key

    Why it's wrong here

    AWS managed keys are created and managed by AWS on the customer's behalf. The customer cannot rotate these keys independently or change their key policies. While they provide encryption at rest, they do not satisfy the requirement for a company-managed key with independent rotation control.

  • ✗

    AWS Secrets Manager

    Why it's wrong here

    AWS Secrets Manager is designed to store and rotate secrets such as database credentials and API keys. It does not provide encryption keys for S3 data at rest. Using it for S3 encryption is not its purpose and would not satisfy the encryption requirement.

  • ✗

    Amazon S3 default encryption with Amazon S3 managed keys (SSE-S3)

    Why it's wrong here

    SSE-S3 uses keys fully managed by Amazon S3. The customer has no control over key rotation or access policies. This does not meet the requirement for a company-managed key, as the keys are not owned or rotatable by the company.

  • ✓

    AWS Key Management Service (AWS KMS) customer managed key

    Why this is correct

    AWS KMS customer managed keys give the company full control over key creation, rotation, and access policies. They can enable automatic rotation and define granular permissions. This meets the requirement for a company-managed key that can be rotated independently, and it integrates with S3 server-side encryption to protect data at rest.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This AIF-C01 question is part of Courseiva's 862-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This AIF-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AIF-C01 exam.