Courseiva
Data Protection →mediumMultiple Select

SCS-C02 Data Protection Practice Question

A company is designing a data protection strategy for Amazon EBS volumes. Which TWO practices should be implemented? (Choose TWO.)

⚠ Common exam trap

SCS-C02 often tests the misconception that S3 Object Lock can be used to protect EBS snapshots, confusing S3 features with EBS capabilities, or that EBS multi-attach provides high availability, when it is actually for concurrent access in clustered applications.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable encryption by default for new EBS volumes

Option A is correct because enabling EBS encryption by default ensures that all newly created EBS volumes in the account/Region are automatically encrypted at rest using AWS KMS keys, protecting data without relying on manual per-volume configuration. Option D is correct because EBS snapshots are incremental, point-in-time backups stored in Amazon S3, and copying them to a different Region provides cross-Region durability and disaster recovery against Regional failures or accidental deletion. Option B is incorrect because S3 Object Lock applies to objects in S3 buckets, not to EBS snapshots, which are managed through EBS snapshot APIs and lifecycle policies. Option C is incorrect because automated backups for Amazon RDS protect RDS databases, not EBS volumes, so it does not address the EBS data protection requirement. Option E is incorrect because EBS Multi-Attach only allows a single io1/io2 volume to be attached to multiple Nitro-based EC2 instances in the same AZ for concurrent access, and it does not provide backup or data protection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable encryption by default for new EBS volumes

    Why this is correct

    Enabling encryption by default for new EBS volumes is a foundational data-at-rest protection control because it automatically encrypts the underlying volume and its snapshots with an AWS KMS key, without requiring per-volume configuration. This prevents raw storage from being accessed if an unauthorized party gains access to the physical media, and it also ensures that any future snapshots derived from these volumes inherit the same encryption, which is mandatory for many compliance frameworks.

  • ✗

    Use S3 Object Lock to prevent deletion of snapshots

    Why it's wrong here

    S3 Object Lock is designed to enforce write-once-read-many (WORM) retention on objects stored in Amazon S3, using legal holds or retention modes to prevent deletion or modification of S3 objects. It has no integration with EBS snapshots, which are stored as Amazon EBS snapshots in the EBS service (not as S3 objects), so it cannot protect them. To prevent snapshot deletion, you would need IAM policies, AWS Backup vault locks, or snapshot lifecycle rules, not Object Lock.

  • ✗

    Enable automated backups for Amazon RDS

    Why it's wrong here

    Automated backups for Amazon RDS protect relational databases by creating transaction logs and automated snapshots of RDS DB instances, which is a database-specific durability feature. EBS volumes are block-level storage attached to EC2 instances and are not covered by RDS backup functionality because RDS backups are managed for the DB engine, not for arbitrary EBS volumes. Even if an EC2 instance hosts a database, the EBS volume's data still requires its own snapshot strategy; RDS automated backups will not capture EBS volume data outside the managed RDS service.

  • ✓

    Take regular snapshots of EBS volumes and store them in a different region

    Why this is correct

    Taking regular snapshots of EBS volumes and copying them to a different region provides both point-in-time recovery and geographic disaster recovery, because EBS snapshots are stored in Amazon S3 within the source region and can be copied cross-region. This approach protects against regional infrastructure failures, accidental deletions, and corruption, allowing you to recreate volumes and EC2 instances in another region using the copied snapshots. It is a core data protection best practice because it ensures backup data is isolated from the primary region's failure domain.

  • ✗

    Use EBS multi-attach for high availability

    Why it's wrong here

    EBS multi-attach allows a single Provisioned IOPS (io1/io2) EBS volume to be attached to multiple EC2 instances simultaneously, which is used for cluster-aware applications like Microsoft SQL Server Failover Cluster Instance or shared-file systems. It does not provide data protection because it only enables multiple instances to read and write to the same volume concurrently; it does not create copies, encryption, or snapshots of the data. In fact, multi-attach can increase data corruption risk if applications do not coordinate writes properly, so it should not be considered a backup or durability mechanism.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.