Courseiva
Data ProtectionhardMultiple SelectObjective-mapped

SCS-C02 Data Protection Practice Question

A company is designing a disaster recovery plan for encrypted Amazon EBS volumes. Which THREE steps are required to ensure that encrypted EBS snapshots can be restored in a different AWS Region?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Copy the encrypted snapshot to the target AWS Region

To restore encrypted EBS snapshots in a different AWS Region, you must copy the encrypted snapshot to the target region (B) and ensure the customer managed key (CMK) used for encryption is available in the target region (D). Re-encrypting the snapshot with a CMK in the target region (A) is optional if you want to use a different key, but it is not a required step. Options C and E are incorrect because AWS CloudHSM is not used for EBS encryption and sharing snapshots via AWS RAM does not guarantee key availability.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Re-encrypt the snapshot with a customer managed key (CMK) in the target region

    Why it's wrong here

    Re-encrypting the snapshot with a CMK in the target region is optional; you can restore the snapshot using the original key if it is available in the target region.

  • Copy the encrypted snapshot to the target AWS Region

    Why this is correct

    The encrypted snapshot must be copied to the target region as the first step in the restoration process.

  • Store the encryption key in AWS CloudHSM in the target region

    Why it's wrong here

    EBS uses KMS keys, not CloudHSM.

  • Ensure the CMK used for encryption is available in the target region

    Why this is correct

    The CMK used to encrypt the snapshot must be available in the target region, either by copying the key or creating a new key with the same material, to decrypt the snapshot.

  • Share the snapshot with the target region using AWS RAM

    Why it's wrong here

    RAM is for resource sharing, but encryption requires additional steps.

About these practice questions

One of 376 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.