Courseiva
Security →easyMultiple Choice

How to Choose the Right S3 Server-Side Encryption Type

A developer needs to encrypt data in an S3 bucket. The company requires that the encryption key be managed by AWS but with the ability to audit key usage. Which S3 encryption option should the developer use?

⚠ Common exam trap

DVA-C02 often tests the difference between SSE-S3 and SSE-KMS regarding auditability; candidates may incorrectly assume SSE-S3 provides key usage logs, but only SSE-KMS integrates with CloudTrail for auditing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Server-Side Encryption with AWS KMS (SSE-KMS).

SSE-KMS uses AWS Key Management Service (KMS) to manage the encryption keys, and it provides audit trails of key usage via AWS CloudTrail. This meets the requirement of AWS-managed keys with auditability. SSE-S3 uses S3-managed keys but does not provide detailed audit logs of key usage. Client-side encryption and SSE-C involve customer-managed keys, which do not meet the 'managed by AWS' requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Server-Side Encryption with AWS KMS (SSE-KMS).

    Why this is correct

    This option is ideal when the company requires robust control and auditability over encryption keys. With SSE-KMS, S3 encrypts objects using a customer master key (CMK) stored in AWS Key Management Service. This enables detailed logging of key usage requests through AWS CloudTrail, providing an essential audit trail for compliance, while AWS KMS handles the secure storage and management of the CMK.

  • ✗

    Client-side encryption.

    Why it's wrong here

    Client-side encryption involves the data being encrypted by the application or client device *before* it is uploaded to S3. The encryption keys are entirely managed by the client, not by AWS, which means AWS has no visibility or control over the keys or the encryption process itself. This approach does not align with a requirement where AWS would manage the encryption keys, as implied by the need for server-side encryption.

  • ✗

    Server-Side Encryption with S3-Managed Keys (SSE-S3).

    Why it's wrong here

    SSE-S3 uses AES-256 encryption to protect data at rest in S3, where AWS manages both the encryption and decryption keys. While it provides strong encryption, the specific encryption keys used are entirely managed by S3, and AWS does not provide direct access to these keys or detailed audit logs of their usage via services like CloudTrail. This lack of key usage auditability makes it unsuitable if the company requires tracking who accessed or used the encryption keys.

  • ✗

    Server-Side Encryption with Customer-Provided Keys (SSE-C).

    Why it's wrong here

    SSE-C allows you to encrypt objects in S3 using an encryption key that you provide as part of the upload request. S3 uses this key to encrypt your data and then discards the key after the operation, requiring you to provide the same key for subsequent retrievals. This method places the full responsibility of key generation, management, and rotation squarely on the customer, directly contradicting any implicit or explicit requirement for AWS to manage the encryption keys.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on DVA-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company wants to encrypt data at rest in an S3 bucket using server-side encryption. Which option provides the MOST control over the encryption key?

easy
  • A.SSE-KMS (AWS KMS keys)
  • ✓ B.SSE-C (customer-provided keys)
  • C.Client-side encryption
  • D.SSE-S3 (S3-managed keys)

Why B: SSE-C (customer-provided keys) gives you the most control because you manage the encryption key yourself—you provide the key in each request, and AWS discards it after use. This means you have full lifecycle control over the key material, including rotation, deletion, and access policies, without AWS ever storing the key. In contrast, SSE-KMS and SSE-S3 rely on AWS-managed or AWS-controlled key stores, reducing your direct control.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.