Courseiva
Design for New Solutions →easyMultiple Choice

SAP-C02 Design for New Solutions Practice Question

A company is designing a new application that will store sensitive customer data in Amazon S3. The company must ensure that the data is encrypted at rest and that the encryption keys are rotated automatically every year. The company also wants to audit key usage. Which solution will meet these requirements?

⚠ Common exam trap

The trap here is assuming that SSE-S3 automatically rotates keys and provides auditing, when in fact auditing key usage requires AWS KMS and customer managed keys.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use server-side encryption with AWS KMS customer managed keys (SSE-KMS) and enable automatic key rotation.

Using SSE-KMS with AWS KMS customer managed keys enables automatic annual key rotation and provides audit trails of key usage via AWS CloudTrail. This meets the requirements for encryption at rest, automatic rotation, and auditing. Customer managed keys also allow the company to control access and lifecycle, which is important for sensitive data. Other encryption options either lack auditing, require manual key management, or add unnecessary complexity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use server-side encryption with customer-provided keys (SSE-C).

    Why it's wrong here

    SSE-C requires the company to provide and manage its own encryption keys with each request. AWS does not store these keys, so there is no automatic key rotation and no built-in auditing of key usage. The company would need to implement its own key rotation and audit mechanisms, which adds operational overhead and does not meet the requirement for automatic rotation and auditing.

  • ✓

    Use server-side encryption with AWS KMS customer managed keys (SSE-KMS) and enable automatic key rotation.

    Why this is correct

    SSE-KMS with customer managed keys allows the company to control the KMS key, enable automatic annual rotation, and audit key usage through AWS CloudTrail. This meets all requirements: encryption at rest, automatic key rotation, and auditing. Customer managed keys also provide granular access control and the ability to disable or revoke the key if needed.

  • ✗

    Use server-side encryption with Amazon S3 managed keys (SSE-S3).

    Why it's wrong here

    SSE-S3 encrypts data at rest with keys managed by Amazon S3, and key rotation is handled automatically. However, SSE-S3 does not provide a way to audit key usage or to control key rotation policies, and it does not use AWS KMS customer managed keys. The requirement to audit key usage implies the need for AWS KMS, which logs key usage to AWS CloudTrail. SSE-S3 does not meet the auditing requirement.

  • ✗

    Use client-side encryption with an AWS KMS customer managed key and store the encrypted data in Amazon S3.

    Why it's wrong here

    Client-side encryption encrypts data before sending it to Amazon S3, and using a KMS customer managed key provides auditing and automatic rotation. However, client-side encryption requires the application to handle encryption and decryption, adding complexity. The scenario does not specify a need for client-side encryption, and server-side encryption with SSE-KMS achieves the same security goals with less effort.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SAP-C02 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.