Courseiva

CLF-C02 Cloud Technology and Services Practice Question

A financial services company must ensure that all data stored in Amazon S3 is encrypted at rest using keys that the company manages and rotates according to its internal security policy. The company also needs to audit key usage separately from other AWS services. Which AWS service should the company use to meet these requirements?

⚠ Common exam trap

The trap here is assuming that SSE-S3 or SSE-C provide customer-managed keys with auditing, but SSE-S3 keys are fully managed by AWS and SSE-C keys are not stored or audited by AWS.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Key Management Service (AWS KMS) with customer managed keys

AWS Key Management Service (AWS KMS) with customer managed keys allows the company to create, manage, and rotate encryption keys according to its policies. It integrates with Amazon S3 to encrypt data at rest, and all key usage is logged in AWS CloudTrail, providing a separate audit trail. The other options either do not allow customer-managed keys or do not provide the required auditing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Amazon S3 server-side encryption with Amazon S3 managed keys (SSE-S3)

    Why it's wrong here

    SSE-S3 uses encryption keys managed entirely by Amazon S3, and the company cannot control key rotation or access policies. It does not provide separate auditing of key usage because the keys are not in the company's control. While it encrypts data at rest, it fails to meet the requirement for customer-managed keys and separate audit trails.

  • ✓

    AWS Key Management Service (AWS KMS) with customer managed keys

    Why this is correct

    AWS KMS allows the creation of customer managed keys that the company controls, including key rotation and access policies. It provides separate audit trails through AWS CloudTrail, enabling the company to monitor key usage independently. Using KMS with customer managed keys meets the requirements for managing encryption keys for S3 data at rest and auditing key usage separately.

  • ✗

    AWS CloudHSM

    Why it's wrong here

    AWS CloudHSM provides dedicated hardware security modules for key storage, but it requires more management overhead and does not integrate as seamlessly with S3 for encryption at rest. While it offers customer-controlled keys, auditing key usage separately would require additional configuration, and it is typically used for specific compliance requirements that mandate dedicated HSMs, not general S3 encryption.

  • ✗

    Amazon S3 server-side encryption with customer-provided keys (SSE-C)

    Why it's wrong here

    SSE-C allows the company to provide its own encryption keys with each request, but AWS does not store these keys. The company is responsible for managing and rotating them, and there is no separate audit trail for key usage because the keys are not managed by an AWS service. This option does not provide the auditing capabilities required.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 993 original CLF-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.