CLF-C02 Security and Compliance Practice Question
A financial services company stores sensitive transaction data in Amazon S3. The company must encrypt the data at rest using keys that are stored in a hardware security module (HSM) validated under FIPS 140-2 Level 3. Additionally, the company requires full control over the key lifecycle, including rotation and deletion, and AWS must not have any access to the keys. Which AWS service should the company use to generate and store the encryption keys?
⚠ Common exam trap
Many exam-takers confuse AWS KMS customer managed keys with full customer control, but KMS still allows AWS to manage the underlying HSM infrastructure and does not meet FIPS 140-2 Level 3 requirements, whereas CloudHSM provides exclusive customer control and a higher validation level.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudHSM
AWS CloudHSM is the correct choice because it provides dedicated hardware security modules (HSMs) that are validated under FIPS 140-2 Level 3, allowing you to generate and store encryption keys entirely within the HSM. With CloudHSM, AWS has no access to your keys, and you retain full control over key lifecycle operations such as rotation and deletion, meeting the strict compliance and security requirements of the financial services company.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Key Management Service (KMS) with a customer managed key
Why it's wrong here
AWS KMS uses shared HSMs and provides FIPS 140-2 Level 2 validation (Level 3 in select regions), but the customer does not have dedicated, isolated HSM hardware. AWS retains some administrative access to the HSM infrastructure. This does not meet the requirement for exclusive customer control and Level 3 validation.
When this WOULD be correct
A company needs to encrypt data at rest with a key that is automatically rotated and managed by AWS, and does not require exclusive control over the HSM or FIPS 140-2 Level 3 validation. In that case, AWS KMS with a customer managed key is appropriate.
- ✓
AWS CloudHSM
Why this is correct
AWS CloudHSM provides dedicated HSMs that are FIPS 140-2 Level 3 validated. Customers have full control over the HSMs and the keys stored inside them, including the ability to rotate and delete keys. AWS cannot access the keys because the HSMs are dedicated to the customer and managed by the customer.
- ✗
AWS Secrets Manager
Why it's wrong here
AWS Secrets Manager is a service for securely storing and rotating secrets (e.g., passwords, API keys). It does not provide dedicated HSM hardware or FIPS 140-2 Level 3 validation. It is not designed for generating or storing encryption keys for data at rest.
When this WOULD be correct
A company needs to automatically rotate database credentials (e.g., RDS passwords) and store them securely. Secrets Manager would be the correct service to manage the secret lifecycle, including rotation and retrieval via API.
- ✗
AWS Certificate Manager (ACM)
Why it's wrong here
AWS Certificate Manager handles SSL/TLS certificate provisioning, renewal, and deployment. It does not generate or store encryption keys for S3 data at rest, nor does it offer dedicated HSM capabilities with FIPS 140-2 Level 3 validation.
When this WOULD be correct
A company needs to manage SSL/TLS certificates for HTTPS endpoints (e.g., CloudFront, ELB) and wants automatic renewal and deployment. ACM would be the correct service to handle certificate lifecycle without manual intervention.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CLF-C02 exam frequently reuses these exact scenarios with slightly different constraints.
✓AWS CloudHSMCorrect answer▾
Why this is correct
AWS CloudHSM provides dedicated HSMs that are FIPS 140-2 Level 3 validated. Customers have full control over the HSMs and the keys stored inside them, including the ability to rotate and delete keys. AWS cannot access the keys because the HSMs are dedicated to the customer and managed by the customer.
✗AWS Key Management Service (KMS) with a customer managed keyWrong answer — click to see why▾
Why this is wrong here
AWS KMS with a customer managed key does not use a hardware security module (HSM) validated under FIPS 140-2 Level 3; it uses FIPS 140-2 Level 2 or Level 3 overall, but AWS retains access to the keys and does not provide exclusive customer control over the HSM.
★ When this WOULD be the correct answer
A company needs to encrypt data at rest with a key that is automatically rotated and managed by AWS, and does not require exclusive control over the HSM or FIPS 140-2 Level 3 validation. In that case, AWS KMS with a customer managed key is appropriate.
Why candidates choose this
Candidates may confuse 'customer managed key' with full control over the key lifecycle, but KMS does not allow the customer to control the underlying HSM or prevent AWS access to the keys.
✗AWS Secrets ManagerWrong answer — click to see why▾
Why this is wrong here
AWS Secrets Manager is designed for securely storing and rotating secrets like database credentials, not for generating or managing encryption keys with FIPS 140-2 Level 3 validated HSMs. It does not provide the required HSM-level key control or prevent AWS access to keys.
★ When this WOULD be the correct answer
A company needs to automatically rotate database credentials (e.g., RDS passwords) and store them securely. Secrets Manager would be the correct service to manage the secret lifecycle, including rotation and retrieval via API.
Why candidates choose this
Candidates may confuse Secrets Manager's ability to store secrets with key management, or assume it can generate encryption keys because it handles sensitive data, overlooking the specific HSM and key control requirements.
✗AWS Certificate Manager (ACM)Wrong answer — click to see why▾
Why this is wrong here
AWS Certificate Manager (ACM) is used to provision, manage, and deploy SSL/TLS certificates, not for generating and storing encryption keys for data at rest in S3. It does not provide FIPS 140-2 Level 3 validated HSM or full customer control over key lifecycle with no AWS access.
★ When this WOULD be the correct answer
A company needs to manage SSL/TLS certificates for HTTPS endpoints (e.g., CloudFront, ELB) and wants automatic renewal and deployment. ACM would be the correct service to handle certificate lifecycle without manual intervention.
Why candidates choose this
Candidates may confuse ACM with key management services because both involve cryptographic operations, or they might think ACM can generate encryption keys for data protection due to its name containing 'Certificate' and 'Management'.
Analysis generated from the official CLF-C02blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 988 original CLF-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.