Courseiva
Security and Compliance →hardMultiple Choice

CLF-C02 Security and Compliance Practice Question

A company stores sensitive financial data in Amazon S3. They need to ensure that even if an attacker gains access to the S3 service, they cannot read the data without a customer-controlled encryption key. Which S3 encryption method satisfies this requirement?

⚠ Common exam trap

Many exam-takers confuse 'customer-managed' with 'AWS managed' and assume any KMS key provides customer control, but only a customer-managed CMK gives the customer exclusive control over the key's lifecycle and permissions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SSE-KMS with a customer-managed CMK

SSE-KMS with a customer-managed CMK ensures that the encryption key is under the customer's exclusive control, not AWS. Even if an attacker gains access to the S3 service, they cannot decrypt the data without the customer-managed CMK, which is stored in AWS KMS and can be further protected with key policies, IAM policies, and optional key rotation. This satisfies the requirement that the attacker cannot read the data without a customer-controlled encryption key.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    SSE-S3 (Amazon S3-managed keys)

    Why it's wrong here

    SSE-S3 uses Amazon S3-managed encryption keys, where AWS fully owns and operates the key hierarchy that encrypts your objects. While the data is encrypted at rest, you have no control over the key material, its rotation schedule, or who can access it—AWS can decrypt the data on your behalf as part of its service. This option does not satisfy the 'customer controls the encryption keys' requirement because the customer cannot set policies, disable keys, or independently audit usage through CloudTrail. It is fundamentally a turnkey AWS-managed encryption solution, not a customer-controlled one.

  • ✗

    SSE-KMS with an AWS managed CMK (aws/s3)

    Why it's wrong here

    SSE-KMS with an AWS managed CMK (aws/s3) still uses AWS Key Management Service, but the CMK is created and managed entirely by AWS. You cannot edit the key policy, cannot manually rotate it, and cannot delete it—AWS controls the key lifecycle and has the authority to use it for decryption. Although some customers think any KMS key gives them control, the 'aws/s3' managed CMK is automatically shared across all AWS services and does not allow customer-defined permissions or audit visibility. This falls short because AWS, not the customer, retains independent control over the encryption key material.

  • ✓

    SSE-KMS with a customer-managed CMK

    Why this is correct

    SSE-KMS with a customer-managed CMK is the only option that gives the customer direct ownership and control over the encryption key. You can define the key policy, set rotation frequency, and delete or disable the key as needed; if you delete the CMK, the S3 objects encrypted with it become permanently unreadable, even by AWS. Every call to use the key is also recorded in AWS CloudTrail, providing an independent audit trail that AWS-managed keys cannot offer. This matches the explicit requirement that the customer must control the encryption keys.

  • ✗

    S3 Versioning with MFA Delete

    Why it's wrong here

    S3 Versioning with MFA Delete is about protecting object versions, not about encryption keys. Versioning retains copies of objects so you can recover from accidental overwrites or deletions, while MFA Delete adds a second authentication factor to permanently remove versions or turn off versioning. Neither feature encrypts your data nor gives you any control over encryption keys; objects remain stored in their original form—plaintext or whatever encryption you separately configured. Therefore, it fails the requirement because it addresses data durability and deletion protection, not encryption key ownership.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 993 original CLF-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.