SCS-C02 Data Protection Practice Question
A company is designing a disaster recovery plan for encrypted Amazon EBS volumes. Which THREE steps are required to ensure that encrypted EBS snapshots can be restored in a different AWS Region?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Copy the encrypted snapshot to the target AWS Region
To restore encrypted EBS snapshots in a different AWS Region, you must copy the encrypted snapshot to the target region (B) and ensure the customer managed key (CMK) used for encryption is available in the target region (D). Re-encrypting the snapshot with a CMK in the target region (A) is optional if you want to use a different key, but it is not a required step. Options C and E are incorrect because AWS CloudHSM is not used for EBS encryption and sharing snapshots via AWS RAM does not guarantee key availability.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Re-encrypt the snapshot with a customer managed key (CMK) in the target region
Why it's wrong here
Re-encrypting the snapshot with a CMK in the target region is optional; you can restore the snapshot using the original key if it is available in the target region.
- ✓
Copy the encrypted snapshot to the target AWS Region
Why this is correct
The encrypted snapshot must be copied to the target region as the first step in the restoration process.
- ✗
Store the encryption key in AWS CloudHSM in the target region
Why it's wrong here
EBS uses KMS keys, not CloudHSM.
- ✓
Ensure the CMK used for encryption is available in the target region
Why this is correct
The CMK used to encrypt the snapshot must be available in the target region, either by copying the key or creating a new key with the same material, to decrypt the snapshot.
- ✗
Share the snapshot with the target region using AWS RAM
Why it's wrong here
RAM is for resource sharing, but encryption requires additional steps.
Go deeper
Related to this question
About these practice questions
One of 376 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.