Courseiva
Data Protection →easyMultiple Choice

SCS-C02 Customer managed KMS key Practice Question

A company needs to protect data at rest on Amazon EBS volumes attached to EC2 instances. Which solution provides the most control over the encryption keys?

⚠ Common exam trap

SCS-C02 often tests the distinction between AWS managed and customer managed KMS keys; candidates incorrectly assume that enabling EBS encryption by default or using an AWS managed key provides the same level of control as a customer managed key.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a customer managed KMS key with EBS encryption.

A customer managed KMS key gives the account owner full control over the key policy, rotation, grants, and deletion, which is the maximum control available for EBS encryption at rest. AWS managed keys (aws/ebs) are controlled by AWS and cannot be customized or have their policies modified by the customer. Enabling EBS encryption by default only sets a default key but does not by itself provide the most control. Client-side encryption is a different layer and does not address EBS-native encryption key control.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use a customer managed KMS key with EBS encryption.

    Why this is correct

    Using a customer managed KMS key with EBS encryption is the correct approach because it gives you full control over the key lifecycle, key policy, and permissions, allowing you to restrict access to specific principals or services. EBS encryption uses envelope encryption where a CMK generates a data key to encrypt the volume, and you can audit key usage through CloudTrail. This provides a native, seamless encryption solution for data at rest without requiring application changes, and it supports compliance requirements that mandate customer-controlled keys.

  • ✗

    Encrypt data using client-side encryption before writing to EBS.

    Why it's wrong here

    Client-side encryption before writing to EBS is not the ideal solution because EBS volumes are block-level storage, and encrypting data at the application layer introduces significant complexity in key management, encryption/decryption logic, and performance overhead. It also does not leverage EBS-native encryption, meaning the volume itself remains unencrypted, which may leave volume snapshots, the underlying storage, and other metadata potentially visible to AWS or in shared environments. Additionally, you lose the ability to use EBS features like encrypted snapshots or volume cloning seamlessly, making this an impractical and less secure choice for a system-level data-at-rest protection requirement.

  • ✗

    Use an AWS managed KMS key for EBS encryption.

    Why it's wrong here

    Using an AWS managed KMS key for EBS encryption provides automated encryption, but these keys are created, managed, and rotated by AWS on your behalf, and you cannot customize the key policy, rotation period, or grants. This lack of control may not satisfy regulatory or internal security policies that require customer-managed keys, and you cannot restrict usage to specific IAM principals or set up fine-grained access controls. While AWS managed keys are suitable for general default encryption, they are not the right answer when the requirement explicitly calls for the customer to have full control over the encryption key, as stated in the correct option.

  • ✗

    Enable EBS encryption by default in the account.

    Why it's wrong here

    Enabling EBS encryption by default in the account is a beneficial security baseline, but it is not a complete answer to the specific requirement because it only affects newly created volumes and, unless you specify a customer managed key, it will use the default AWS managed key (aws/ebs). This default behavior does not give you the same control over key permissions, rotation, or lifecycle as a customer managed key, and it does not automatically encrypt existing volumes. The question asks for a direct method to protect data at rest on an EBS volume, so while default encryption is a good practice, it is not the precise, customizable solution that a customer managed key provides.

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.