SCS-C02 Data Protection Practice Question
A company is designing a data protection strategy for its Amazon RDS for PostgreSQL database. The database contains sensitive customer data. Compliance requirements mandate that all backups be encrypted at rest and that the encryption keys be rotated annually. Which solution meets these requirements?
⚠ Common exam trap
SCS-C02 often tests the difference between AWS managed and customer managed KMS keys, tempting candidates to pick AWS managed keys when the requirement specifies customer-controlled annual rotation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable encryption at rest on the RDS instance using a customer managed KMS key. Enable automatic key rotation in KMS.
Enabling encryption at rest on the RDS instance with a customer managed KMS key gives the company control over the key, and enabling automatic key rotation in KMS satisfies the annual rotation requirement. Customer managed keys support automatic rotation (default 365 days), unlike AWS managed keys, which cannot be rotated on a customer-defined schedule.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create an encrypted read replica of the RDS instance and use the replica for backups.
Why it's wrong here
A read replica encrypts its own storage but does not encrypt the primary instance's automated backups, which retain the primary's unencrypted state. It is tempting because encrypted read replicas are a valid way to obtain encrypted copies of data for reporting or backup workloads when the source is already encrypted.
- ✗
Use S3 server-side encryption with a customer managed key for automated backups. Configure lifecycle policies to rotate the key.
Why it's wrong here
RDS automated backups are encrypted with the KMS key protecting the DB instance, not with S3 server-side encryption; S3 SSE and lifecycle policies cannot rotate that key. It is tempting because S3 SSE with customer managed keys and lifecycle actions is the standard approach for encrypting and rotating keys on objects stored in S3 buckets.
- ✗
Enable encryption at rest on the RDS instance using an AWS managed KMS key. The key will be rotated automatically every year.
Why it's wrong here
AWS managed KMS keys rotate automatically every year, but their rotation schedule and key policy cannot be customised to meet a compliance-mandated annual rotation with audit evidence. It is tempting because AWS managed keys do rotate annually by default, which would satisfy a requirement that merely asks for automatic yearly rotation without customer control.
- ✓
Enable encryption at rest on the RDS instance using a customer managed KMS key. Enable automatic key rotation in KMS.
Why this is correct
Customer managed KMS keys with automatic rotation satisfy both mandates: RDS backups inherit the instance's encryption at rest, and KMS rotates the key annually. AWS managed keys do not offer customer-controlled rotation, so they fail the compliance requirement.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.