Courseiva
Security →easyMultiple Choice

DVA-C02 Security Practice Question

A developer is encrypting an S3 bucket using server-side encryption with AWS KMS (SSE-KMS). What is a benefit of using SSE-KMS over SSE-S3?

⚠ Common exam trap

DVA-C02 often tests the differences between S3 encryption options. Candidates may think SSE-KMS is always faster or cheaper, but it actually adds latency and cost due to KMS operations. The key benefit is control and auditability.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ability to control access to the encryption key separately

SSE-KMS allows you to use AWS KMS customer master keys (CMKs) to encrypt objects, giving you control over key access through KMS key policies and IAM. This separation of key management from data management is a key benefit over SSE-S3, where AWS manages the keys entirely. Thus, the ability to control access to the encryption key separately is the correct benefit.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Reduced latency for encrypted object retrieval

    Why it's wrong here

    SSE-KMS introduces an additional step of calling the AWS Key Management Service (KMS) to decrypt the data key before the actual object data can be decrypted. This envelope encryption process, involving an extra network round trip and cryptographic operation, inherently adds a slight overhead, thereby increasing rather than reducing latency for object retrieval compared to unencrypted or SSE-S3 operations. Therefore, reduced latency is not a benefit of SSE-KMS.

  • ✗

    Lower cost than SSE-S3

    Why it's wrong here

    SSE-KMS incurs specific costs associated with AWS Key Management Service (KMS), including charges for API requests made to encrypt and decrypt data keys, as well as monthly fees for storing Customer Master Keys (CMKs). In contrast, SSE-S3 handles all key management within the S3 service without explicit additional charges beyond standard S3 storage and request fees. Consequently, SSE-KMS is typically more expensive than SSE-S3 due to these KMS usage fees.

  • ✓

    Ability to control access to the encryption key separately

    Why this is correct

    SSE-KMS provides enhanced security by allowing the encryption key, known as a Customer Master Key (CMK), to be managed independently within AWS KMS. Access to these CMKs is governed by dedicated key policies and IAM policies, enabling granular control over who can use the key for cryptographic operations, separate from S3 bucket permissions. This distinct management allows for a robust separation of duties, ensuring that access to data and access to its encryption key are controlled and auditable independently.

  • ✗

    Automatic encryption of objects at rest

    Why it's wrong here

    While SSE-KMS does provide automatic encryption of objects at rest, this is not a unique benefit that distinguishes it from other server-side encryption options. Server-Side Encryption with S3-managed keys (SSE-S3) also automatically encrypts objects at rest using keys entirely managed by AWS S3, requiring no additional configuration from the user. Therefore, automatic encryption at rest is a common feature of server-side encryption in S3, not an exclusive advantage of SSE-KMS.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.