CLF-C02 Cloud Technology and Services Practice Question
A financial services company must ensure that all data stored in Amazon S3 is encrypted at rest using keys that the company manages and rotates according to its internal security policy. The company also needs to audit key usage separately from other AWS services. Which AWS service should the company use to meet these requirements?
⚠ Common exam trap
The trap here is assuming that SSE-S3 or SSE-C provide customer-managed keys with auditing, but SSE-S3 keys are fully managed by AWS and SSE-C keys are not stored or audited by AWS.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Key Management Service (AWS KMS) with customer managed keys
AWS Key Management Service (AWS KMS) with customer managed keys allows the company to create, manage, and rotate encryption keys according to its policies. It integrates with Amazon S3 to encrypt data at rest, and all key usage is logged in AWS CloudTrail, providing a separate audit trail. The other options either do not allow customer-managed keys or do not provide the required auditing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon S3 server-side encryption with Amazon S3 managed keys (SSE-S3)
Why it's wrong here
SSE-S3 uses encryption keys managed entirely by Amazon S3, and the company cannot control key rotation or access policies. It does not provide separate auditing of key usage because the keys are not in the company's control. While it encrypts data at rest, it fails to meet the requirement for customer-managed keys and separate audit trails.
- ✓
AWS Key Management Service (AWS KMS) with customer managed keys
Why this is correct
AWS KMS allows the creation of customer managed keys that the company controls, including key rotation and access policies. It provides separate audit trails through AWS CloudTrail, enabling the company to monitor key usage independently. Using KMS with customer managed keys meets the requirements for managing encryption keys for S3 data at rest and auditing key usage separately.
- ✗
AWS CloudHSM
Why it's wrong here
AWS CloudHSM provides dedicated hardware security modules for key storage, but it requires more management overhead and does not integrate as seamlessly with S3 for encryption at rest. While it offers customer-controlled keys, auditing key usage separately would require additional configuration, and it is typically used for specific compliance requirements that mandate dedicated HSMs, not general S3 encryption.
- ✗
Amazon S3 server-side encryption with customer-provided keys (SSE-C)
Why it's wrong here
SSE-C allows the company to provide its own encryption keys with each request, but AWS does not store these keys. The company is responsible for managing and rotating them, and there is no separate audit trail for key usage because the keys are not managed by an AWS service. This option does not provide the auditing capabilities required.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 993 original CLF-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.