Courseiva
Security →easyMultiple Select

DVA-C02 SSE-S3 Practice Question

Which TWO services can be used to encrypt data at rest in Amazon S3? (Choose two.)

⚠ Common exam trap

Candidates often confuse the two server-side encryption options (SSE-S3 and SSE-KMS) and may forget that both can encrypt data at rest in S3. Also, IAM and ACM are not encryption services.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SSE-KMS

Options A and E are correct. Option A: SSE-KMS uses AWS Key Management Service (KMS) for managing encryption keys, providing additional control and audit capabilities. Option E: SSE-S3 uses S3-managed keys for encryption at rest. Option B is incorrect because AWS IAM is an access management service, not an encryption service. Option C is incorrect because AWS Certificate Manager (ACM) handles SSL/TLS certificates, not data encryption. Option D is incorrect because AWS CloudHSM provides hardware security modules but is not directly integrated with S3 for encryption.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    SSE-KMS

    Why this is correct

    SSE-KMS encrypts each object using a data key generated and protected by an AWS KMS customer managed or AWS managed key, giving administrators fine-grained IAM control over who can use the key, a full CloudTrail audit trail of key usage, and support for key rotation.

  • ✗

    AWS IAM

    Why it's wrong here

    AWS IAM manages users, groups, roles, and permission policies to control who can perform which actions on which resources; it has no role in encrypting object bytes at rest and is unrelated to S3's server-side encryption mechanisms.

  • ✗

    AWS Certificate Manager (ACM)

    Why it's wrong here

    ACM issues and manages TLS certificates for data in transit; it does not encrypt S3 objects at rest. It is tempting because ACM is an AWS security service often paired with S3 static website endpoints, but server-side encryption is provided by SSE-S3, SSE-KMS, or SSE-C instead.

  • ✗

    AWS CloudHSM

    Why it's wrong here

    AWS CloudHSM provisions dedicated, single-tenant hardware security modules primarily used for custom cryptographic operations and generating KMS custom key stores; it is not one of S3's supported server-side encryption options (SSE-S3, SSE-KMS, SSE-C) for encrypting objects at rest.

  • ✓

    SSE-S3

    Why this is correct

    SSE-S3 (Amazon S3 managed keys) automatically encrypts every object using AES-256 with keys that AWS generates, rotates, and manages entirely on the customer's behalf, requiring no key management overhead and being the default encryption applied to all new S3 objects.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.