SCS-C02 Data Protection Practice Question
A company is storing sensitive data in Amazon S3. They want to ensure that all data is encrypted at rest using server-side encryption. Which THREE options are available for server-side encryption in S3? (Select THREE.)
⚠ Common exam trap
SCS-C02 often tests the distinction between server-side and client-side encryption — candidates may incorrectly include client-side encryption or CloudHSM as S3 SSE options.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SSE-KMS
SSE-KMS (B) is a valid S3 server-side encryption option in which S3 encrypts objects using keys managed by AWS KMS, giving you control over key policies, audit trails via CloudTrail, and separation of permissions. SSE-S3 (C) is also correct: S3 manages the encryption keys entirely with AES-256, and it is the default server-side encryption applied to objects at rest. SSE-C (D) is correct as well: the customer provides the encryption key on each request, and S3 performs the encryption/decryption server-side without storing the key. Client-side encryption (A) is not server-side encryption because data is encrypted before it reaches S3, so S3 never performs the encryption. AWS CloudHSM (E) is a dedicated hardware security module service, not an S3 server-side encryption option, though it can be used with SSE-C or custom key management.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Client-side encryption
Why it's wrong here
Client-side encryption occurs before data reaches S3, meaning the encryption keys are managed and applied on the client side, not by the S3 service itself. This fails the requirement for *server-side* encryption, which mandates that S3 handles the encryption at rest. It is tempting because it still encrypts data, and would be correct if the compliance requirement were to control encryption keys entirely outside AWS, such as when using a customer-managed key store not integrated with S3.
- ✓
SSE-KMS
Why this is correct
SSE-KMS integrates Amazon S3 with AWS Key Management Service to perform server-side encryption using envelope encryption: S3 calls KMS to generate a data key, encrypts the object with it, and stores the encrypted data key alongside the object. It supports customer-managed KMS keys, enabling granular access control through IAM and KMS policies, automatic key rotation, and audit logs via CloudTrail. This makes it particularly suitable for sensitive data requiring separation of duties and compliance traceability, though it is only one of several valid S3 server-side encryption options.
- ✓
SSE-S3
Why this is correct
SSE-S3 automatically encrypts objects at rest with AES-256 using S3-managed keys, requiring no additional configuration beyond enabling the encryption setting. All key management, including rotation, is handled entirely by AWS, but you cannot inspect the keys, control rotation schedules, or apply custom key policies to individual buckets or objects. While a valid server-side encryption option, it offers less key control and auditability than SSE-KMS or SSE-C, making it acceptable for generic sensitive data but not for scenarios with strict key governance.
- ✓
SSE-C
Why this is correct
SSE-C allows S3 to perform server-side encryption using a customer-provided AES-256 key that is passed in the S3 API request headers, and S3 discards that key immediately after the operation, retaining only an HMAC-based verifier to validate object integrity on subsequent access. The customer must manage and securely store the encryption keys outside AWS, and must include the key with every read or write request, which is operationally complex. It is valid server-side encryption because encryption occurs on S3's server side, but the customer retains complete custody of the keys—unlike SSE-KMS or SSE-S3 where AWS manages key storage.
- ✗
AWS CloudHSM
Why it's wrong here
AWS CloudHSM provides dedicated hardware security modules (HSMs) for generating and storing encryption keys, but it is not a native server-side encryption option for Amazon S3. To use CloudHSM-managed keys with S3, you must implement client-side encryption in your application and upload ciphertext, which defeats the requirement if S3 itself is expected to encrypt the data at rest. Although CloudHSM offers FIPS-validated key storage, it was not designed to integrate as an S3 encryption mode, unlike SSE-KMS, SSE-S3, or SSE-C.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.