CLF-C02 Security and Compliance Practice Question
A company stores sensitive financial data in Amazon S3. They need to ensure that even if an attacker gains access to the S3 service, they cannot read the data without a customer-controlled encryption key. Which S3 encryption method satisfies this requirement?
⚠ Common exam trap
Many exam-takers confuse 'customer-managed' with 'AWS managed' and assume any KMS key provides customer control, but only a customer-managed CMK gives the customer exclusive control over the key's lifecycle and permissions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SSE-KMS with a customer-managed CMK
SSE-KMS with a customer-managed CMK ensures that the encryption key is under the customer's exclusive control, not AWS. Even if an attacker gains access to the S3 service, they cannot decrypt the data without the customer-managed CMK, which is stored in AWS KMS and can be further protected with key policies, IAM policies, and optional key rotation. This satisfies the requirement that the attacker cannot read the data without a customer-controlled encryption key.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
SSE-S3 (Amazon S3-managed keys)
Why it's wrong here
SSE-S3 uses Amazon S3-managed encryption keys, where AWS fully owns and operates the key hierarchy that encrypts your objects. While the data is encrypted at rest, you have no control over the key material, its rotation schedule, or who can access it—AWS can decrypt the data on your behalf as part of its service. This option does not satisfy the 'customer controls the encryption keys' requirement because the customer cannot set policies, disable keys, or independently audit usage through CloudTrail. It is fundamentally a turnkey AWS-managed encryption solution, not a customer-controlled one.
- ✗
SSE-KMS with an AWS managed CMK (aws/s3)
Why it's wrong here
SSE-KMS with an AWS managed CMK (aws/s3) still uses AWS Key Management Service, but the CMK is created and managed entirely by AWS. You cannot edit the key policy, cannot manually rotate it, and cannot delete it—AWS controls the key lifecycle and has the authority to use it for decryption. Although some customers think any KMS key gives them control, the 'aws/s3' managed CMK is automatically shared across all AWS services and does not allow customer-defined permissions or audit visibility. This falls short because AWS, not the customer, retains independent control over the encryption key material.
- ✓
SSE-KMS with a customer-managed CMK
Why this is correct
SSE-KMS with a customer-managed CMK is the only option that gives the customer direct ownership and control over the encryption key. You can define the key policy, set rotation frequency, and delete or disable the key as needed; if you delete the CMK, the S3 objects encrypted with it become permanently unreadable, even by AWS. Every call to use the key is also recorded in AWS CloudTrail, providing an independent audit trail that AWS-managed keys cannot offer. This matches the explicit requirement that the customer must control the encryption keys.
- ✗
S3 Versioning with MFA Delete
Why it's wrong here
S3 Versioning with MFA Delete is about protecting object versions, not about encryption keys. Versioning retains copies of objects so you can recover from accidental overwrites or deletions, while MFA Delete adds a second authentication factor to permanently remove versions or turn off versioning. Neither feature encrypts your data nor gives you any control over encryption keys; objects remain stored in their original form—plaintext or whatever encryption you separately configured. Therefore, it fails the requirement because it addresses data durability and deletion protection, not encryption key ownership.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 993 original CLF-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.