Courseiva
Data Protection →hardMultiple Choice

SCS-C02 Data Protection Practice Question

A company is designing a data protection strategy for sensitive data stored in Amazon S3. Compliance requirements mandate that all data be encrypted at rest using customer-provided keys (SSE-C). Which solution meets the requirements with minimal operational overhead?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use server-side encryption with customer-provided keys (SSE-C) and store the keys in AWS Secrets Manager.

Server-side encryption with customer-provided keys (SSE-C) allows the customer to supply their own encryption keys while AWS manages the encryption/decryption process, meeting compliance requirements with minimal operational overhead. Storing the keys in AWS Secrets Manager adds convenience and security. Option A is incorrect because SSE-S3 uses AWS-managed keys, not customer-provided keys. Option B is incorrect because client-side encryption with the AWS Encryption SDK requires the application to handle encryption, increasing overhead and complexity, and it does not use SSE-C. Option D is incorrect because SSE-KMS uses AWS KMS managed keys, not customer-provided keys, even if key rotation is enabled.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use server-side encryption with Amazon S3 managed keys (SSE-S3) and enable bucket versioning.

    Why it's wrong here

    SSE-S3 encrypts objects with AES-256 using keys that Amazon S3 fully manages. You have no visibility into key material, cannot rotate or revoke keys independently, and lack separation of duties between storage and key administration. Enabling bucket versioning protects against accidental deletion or overwrite, but it does not address a requirement for customer-supplied encryption keys.

  • ✗

    Use client-side encryption with the AWS Encryption SDK and store keys in the application configuration.

    Why it's wrong here

    Client-side encryption with the AWS Encryption SDK encrypts data before it leaves your environment, but storing master keys in application configuration is a serious security risk. Those keys are often in plaintext, difficult to rotate, and accessible to application code, and AWS does not provide a managed store for them in this model. This also increases operational complexity because you must implement your own key management, access auditing, and versioning instead of using a managed service like AWS Secrets Manager or AWS KMS.

  • ✓

    Use server-side encryption with customer-provided keys (SSE-C) and store the keys in AWS Secrets Manager.

    Why this is correct

    SSE-C allows you to provide your own encryption keys in S3 API request headers, and S3 uses them for AES-256 encryption/decryption but never stores the key material, giving you full control over the key lifecycle. Storing those keys in AWS Secrets Manager adds secure storage, centralizes access control, and enables programmatic retrieval for uploads/downloads while keeping the key material customer-owned. This directly satisfies a bring-your-own-key requirement without the overhead of client-side encryption, though you must use HTTPS and supply the key on every request.

  • ✗

    Use server-side encryption with AWS KMS managed keys (SSE-KMS) and enable automatic key rotation.

    Why it's wrong here

    SSE-KMS with automatic key rotation provides envelope encryption and supports customer-managed keys, but the key material is still created and stored by AWS KMS, not supplied by you as customer-provided keys. Even if you choose a customer-managed KMS key, AWS manages the underlying hardware and key lifecycle; automatic rotation occurs on a schedule, not at your explicit direction per object. If the requirement specifically demands customer-supplied encryption keys, SSE-KMS does not provide that control model, making SSE-C the appropriate choice.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.