SCS-C02 Data Protection Practice Question
A company is designing a data protection strategy for sensitive data stored in Amazon S3. Compliance requirements mandate that all data be encrypted at rest using customer-provided keys (SSE-C). Which solution meets the requirements with minimal operational overhead?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use server-side encryption with customer-provided keys (SSE-C) and store the keys in AWS Secrets Manager.
Server-side encryption with customer-provided keys (SSE-C) allows the customer to supply their own encryption keys while AWS manages the encryption/decryption process, meeting compliance requirements with minimal operational overhead. Storing the keys in AWS Secrets Manager adds convenience and security. Option A is incorrect because SSE-S3 uses AWS-managed keys, not customer-provided keys. Option B is incorrect because client-side encryption with the AWS Encryption SDK requires the application to handle encryption, increasing overhead and complexity, and it does not use SSE-C. Option D is incorrect because SSE-KMS uses AWS KMS managed keys, not customer-provided keys, even if key rotation is enabled.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use server-side encryption with Amazon S3 managed keys (SSE-S3) and enable bucket versioning.
Why it's wrong here
SSE-S3 encrypts objects with AES-256 using keys that Amazon S3 fully manages. You have no visibility into key material, cannot rotate or revoke keys independently, and lack separation of duties between storage and key administration. Enabling bucket versioning protects against accidental deletion or overwrite, but it does not address a requirement for customer-supplied encryption keys.
- ✗
Use client-side encryption with the AWS Encryption SDK and store keys in the application configuration.
Why it's wrong here
Client-side encryption with the AWS Encryption SDK encrypts data before it leaves your environment, but storing master keys in application configuration is a serious security risk. Those keys are often in plaintext, difficult to rotate, and accessible to application code, and AWS does not provide a managed store for them in this model. This also increases operational complexity because you must implement your own key management, access auditing, and versioning instead of using a managed service like AWS Secrets Manager or AWS KMS.
- ✓
Use server-side encryption with customer-provided keys (SSE-C) and store the keys in AWS Secrets Manager.
Why this is correct
SSE-C allows you to provide your own encryption keys in S3 API request headers, and S3 uses them for AES-256 encryption/decryption but never stores the key material, giving you full control over the key lifecycle. Storing those keys in AWS Secrets Manager adds secure storage, centralizes access control, and enables programmatic retrieval for uploads/downloads while keeping the key material customer-owned. This directly satisfies a bring-your-own-key requirement without the overhead of client-side encryption, though you must use HTTPS and supply the key on every request.
- ✗
Use server-side encryption with AWS KMS managed keys (SSE-KMS) and enable automatic key rotation.
Why it's wrong here
SSE-KMS with automatic key rotation provides envelope encryption and supports customer-managed keys, but the key material is still created and stored by AWS KMS, not supplied by you as customer-provided keys. Even if you choose a customer-managed KMS key, AWS manages the underlying hardware and key lifecycle; automatic rotation occurs on a schedule, not at your explicit direction per object. If the requirement specifically demands customer-supplied encryption keys, SSE-KMS does not provide that control model, making SSE-C the appropriate choice.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.