Courseiva
Design for New Solutions →hardMultiple Choice

SAP-C02 Design for New Solutions Practice Question

A financial services company is designing a new application that will store sensitive customer data in Amazon S3. The company must encrypt the data at rest and ensure that the encryption keys are rotated annually. The security team requires that the company retains full control over the key rotation and can audit key usage. The solutions architect needs to recommend an encryption solution that meets these requirements with minimal operational effort. Which solution should the architect recommend?

⚠ Common exam trap

A common mix-up: candidates confuse AWS managed keys with customer managed keys, and assuming that AWS managed keys support automatic rotation and auditing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use SSE-KMS with a customer managed key (CMK) and enable automatic key rotation.

SSE-KMS with a customer managed key provides the company with full control over the encryption keys, including the ability to enable automatic annual rotation. It also integrates with AWS CloudTrail for auditing key usage. This solution is fully managed, requiring minimal operational effort. Other options either do not provide the required control or require more management overhead.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use client-side encryption with a custom encryption library and store the keys in AWS Secrets Manager.

    Why it's wrong here

    Client-side encryption gives the company full control over keys and rotation, but it requires managing the encryption library, key rotation logic, and integration, which increases operational effort. The requirement is minimal operational effort, so this approach is not ideal. Additionally, auditing key usage would require custom logging.

  • ✗

    Use SSE-S3 with default encryption and enable S3 bucket key.

    Why it's wrong here

    SSE-S3 uses encryption keys managed by AWS, and the company does not have control over key rotation or auditing. The requirement is to retain full control over key rotation and audit key usage, which SSE-S3 does not provide. Although it is the simplest option, it does not meet the security team's requirements.

  • ✓

    Use SSE-KMS with a customer managed key (CMK) and enable automatic key rotation.

    Why this is correct

    SSE-KMS with a customer managed key allows the company to control key rotation, audit key usage via AWS CloudTrail, and define key policies. Enabling automatic key rotation rotates the key annually, meeting the requirement with minimal operational effort. This solution provides the necessary control and auditability while being fully managed.

  • ✗

    Use SSE-KMS with an AWS managed key and enable automatic key rotation.

    Why it's wrong here

    AWS managed keys are managed by AWS, and the company cannot control key rotation or audit key usage. Automatic key rotation is not available for AWS managed keys; only customer managed keys support automatic rotation. This option does not meet the requirement for full control and auditability.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SAP-C02 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.