Courseiva
Security and Compliance →mediumMultiple Choice

CLF-C02 Security and Compliance Practice Question

Which AWS service provides a managed way to create, control, and rotate encryption keys used to protect your data?

⚠ Common exam trap

Test-takers frequently confuse AWS Secrets Manager (which rotates secrets) with KMS (which rotates encryption keys), but Secrets Manager does not create or manage the encryption keys themselves—it uses KMS for that purpose.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Key Management Service (KMS)

AWS Key Management Service (KMS) is the correct answer because it is a fully managed service that allows you to create, control, and rotate encryption keys used to protect your data. KMS integrates with other AWS services to encrypt data at rest and provides centralized key management, including automatic annual rotation for customer-managed keys. It uses hardware security modules (HSMs) to protect key material, but the service itself handles the management and rotation lifecycle.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Certificate Manager

    Why it's wrong here

    AWS Certificate Manager provisions, manages and renews TLS/SSL certificates for use with AWS services; it does not create or rotate the underlying encryption keys protecting data. It is tempting because it is a managed key-adjacent service, but its scope is public certificate lifecycle, not customer master key management.

  • ✗

    AWS Secrets Manager

    Why it's wrong here

    AWS Secrets Manager stores and rotates credentials, API keys and database passwords, not the encryption keys themselves. It is tempting because rotation is a shared feature, but Secrets Manager rotates secrets, whereas the scenario requires generating and controlling key material for data encryption.

  • ✓

    AWS Key Management Service (KMS)

    Why this is correct

    AWS KMS is the managed service for creating, controlling, and rotating the cryptographic keys that protect your data. It centralises key lifecycle management and integrates with other AWS services, directly meeting the requirement for managed key creation, control, and rotation.

  • ✗

    AWS CloudHSM

    Why it's wrong here

    CloudHSM provides dedicated hardware security modules where you manage keys yourself; it is not a managed key-creation, control and rotation service. It suits compliance regimes demanding single-tenant HSM control. AWS KMS is the managed service that creates, controls and rotates encryption keys.

About these practice questions

This CLF-C02 question is part of Courseiva's 993-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.