Courseiva
Data ProtectionmediumMultiple SelectObjective-mapped

SCS-C02 Data Protection Practice Question

A company is designing a secure data sharing solution with a third party. The company needs to share sensitive files stored in an S3 bucket with the third party, ensuring that the files are encrypted at rest and in transit, and that the third party can only access specific files. The company also wants to rotate the access credentials every 30 days. Which TWO actions should the company take? (Select TWO.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Configure an S3 bucket policy that denies access unless the request includes a specific KMS key ID.

Options C and E are correct. Option C uses an S3 bucket policy with a condition requiring requests to include a specific KMS key ID, ensuring that only requests using that key can access the objects. This enforces encryption at rest (objects encrypted with that key) and in transit (HTTPS with KMS). Option E grants the third party's AWS account permission to use that KMS key for decrypt operations, allowing them to decrypt the files. Together, they provide encryption key control and the ability to rotate the key or its policy every 30 days. Option A (cross-account IAM role) does not enforce encryption key control and requires the third party to assume a role, but credential rotation is managed via role trust policy, not directly. Option B (S3 Cross-Region Replication) replicates objects but does not enforce key-specific access or encryption at rest in the destination. Option D (presigned URLs) provides time-limited access but does not enforce encryption key control and cannot be easily rotated every 30 days without regenerating URLs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Create an IAM role in the company's account that the third party can assume, and attach a policy that grants access to the specific files.

    Why it's wrong here

    This requires the third party to assume a role, which may not be feasible and does not enforce encryption key control.

  • Use S3 Cross-Region Replication to replicate the files to a bucket in the third party's account.

    Why it's wrong here

    Replication does not provide access control or encryption key enforcement.

  • Configure an S3 bucket policy that denies access unless the request includes a specific KMS key ID.

    Why this is correct

    Enforces that only objects encrypted with the specified key can be accessed.

  • Generate presigned URLs for the specific files and email them to the third party.

    Why it's wrong here

    Presigned URLs do not provide encryption key control and are not easily rotated every 30 days.

  • Use a KMS key policy that grants the third party's AWS account permission to use the key for decrypt operations.

    Why this is correct

    Allows the third party to decrypt objects encrypted with that key.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SCS-C02 question is part of Courseiva's 376-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.