DVA-C02 Security Practice Question
A developer is encrypting an S3 bucket using server-side encryption with AWS KMS (SSE-KMS). What is a benefit of using SSE-KMS over SSE-S3?
⚠ Common exam trap
DVA-C02 often tests the differences between S3 encryption options. Candidates may think SSE-KMS is always faster or cheaper, but it actually adds latency and cost due to KMS operations. The key benefit is control and auditability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ability to control access to the encryption key separately
SSE-KMS allows you to use AWS KMS customer master keys (CMKs) to encrypt objects, giving you control over key access through KMS key policies and IAM. This separation of key management from data management is a key benefit over SSE-S3, where AWS manages the keys entirely. Thus, the ability to control access to the encryption key separately is the correct benefit.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reduced latency for encrypted object retrieval
Why it's wrong here
SSE-KMS introduces an additional step of calling the AWS Key Management Service (KMS) to decrypt the data key before the actual object data can be decrypted. This envelope encryption process, involving an extra network round trip and cryptographic operation, inherently adds a slight overhead, thereby increasing rather than reducing latency for object retrieval compared to unencrypted or SSE-S3 operations. Therefore, reduced latency is not a benefit of SSE-KMS.
- ✗
Lower cost than SSE-S3
Why it's wrong here
SSE-KMS incurs specific costs associated with AWS Key Management Service (KMS), including charges for API requests made to encrypt and decrypt data keys, as well as monthly fees for storing Customer Master Keys (CMKs). In contrast, SSE-S3 handles all key management within the S3 service without explicit additional charges beyond standard S3 storage and request fees. Consequently, SSE-KMS is typically more expensive than SSE-S3 due to these KMS usage fees.
- ✓
Ability to control access to the encryption key separately
Why this is correct
SSE-KMS provides enhanced security by allowing the encryption key, known as a Customer Master Key (CMK), to be managed independently within AWS KMS. Access to these CMKs is governed by dedicated key policies and IAM policies, enabling granular control over who can use the key for cryptographic operations, separate from S3 bucket permissions. This distinct management allows for a robust separation of duties, ensuring that access to data and access to its encryption key are controlled and auditable independently.
- ✗
Automatic encryption of objects at rest
Why it's wrong here
While SSE-KMS does provide automatic encryption of objects at rest, this is not a unique benefit that distinguishes it from other server-side encryption options. Server-Side Encryption with S3-managed keys (SSE-S3) also automatically encrypts objects at rest using keys entirely managed by AWS S3, requiring no additional configuration from the user. Therefore, automatic encryption at rest is a common feature of server-side encryption in S3, not an exclusive advantage of SSE-KMS.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.