DVA-C02 SSE-S3 Practice Question
Which TWO services can be used to encrypt data at rest in Amazon S3? (Choose two.)
⚠ Common exam trap
Candidates often confuse the two server-side encryption options (SSE-S3 and SSE-KMS) and may forget that both can encrypt data at rest in S3. Also, IAM and ACM are not encryption services.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SSE-KMS
Options A and E are correct. Option A: SSE-KMS uses AWS Key Management Service (KMS) for managing encryption keys, providing additional control and audit capabilities. Option E: SSE-S3 uses S3-managed keys for encryption at rest. Option B is incorrect because AWS IAM is an access management service, not an encryption service. Option C is incorrect because AWS Certificate Manager (ACM) handles SSL/TLS certificates, not data encryption. Option D is incorrect because AWS CloudHSM provides hardware security modules but is not directly integrated with S3 for encryption.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
SSE-KMS
Why this is correct
SSE-KMS encrypts each object using a data key generated and protected by an AWS KMS customer managed or AWS managed key, giving administrators fine-grained IAM control over who can use the key, a full CloudTrail audit trail of key usage, and support for key rotation.
- ✗
AWS IAM
Why it's wrong here
AWS IAM manages users, groups, roles, and permission policies to control who can perform which actions on which resources; it has no role in encrypting object bytes at rest and is unrelated to S3's server-side encryption mechanisms.
- ✗
AWS Certificate Manager (ACM)
Why it's wrong here
ACM issues and manages TLS certificates for data in transit; it does not encrypt S3 objects at rest. It is tempting because ACM is an AWS security service often paired with S3 static website endpoints, but server-side encryption is provided by SSE-S3, SSE-KMS, or SSE-C instead.
- ✗
AWS CloudHSM
Why it's wrong here
AWS CloudHSM provisions dedicated, single-tenant hardware security modules primarily used for custom cryptographic operations and generating KMS custom key stores; it is not one of S3's supported server-side encryption options (SSE-S3, SSE-KMS, SSE-C) for encrypting objects at rest.
- ✓
SSE-S3
Why this is correct
SSE-S3 (Amazon S3 managed keys) automatically encrypts every object using AES-256 with keys that AWS generates, rotates, and manages entirely on the customer's behalf, requiring no key management overhead and being the default encryption applied to all new S3 objects.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.