Courseiva
Data Protection →mediumMultiple Choice

SCS-C02 Data Protection Practice Question

A company runs a web application on Amazon EC2 instances that processes credit card data. The application must store the data in an encrypted format. The security team wants to minimize the performance impact of encryption and offload the encryption operations to a dedicated hardware security module (HSM). Which solution should the architect choose?

⚠ Common exam trap

SCS-C02 often tests the confusion between AWS KMS and CloudHSM, where candidates think KMS provides dedicated HSM offload, but KMS is a multi-tenant service and does not offload encryption operations from the application.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use AWS CloudHSM to perform encryption operations from the application.

AWS CloudHSM provides dedicated hardware security modules that can perform cryptographic operations, including encryption, offloading the work from the application's CPU. It is designed for applications that require dedicated HSM hardware for compliance or performance reasons. Using CloudHSM allows the application to call the HSM for encryption, minimizing performance impact on the EC2 instance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use Amazon EBS encryption on the EC2 instance's root volume.

    Why it's wrong here

    EBS encryption does not offload application-level encryption operations.

  • ✗

    Use the Linux dm-crypt utility to encrypt the data at the application level.

    Why it's wrong here

    Application-level encryption adds CPU overhead.

  • ✓

    Use AWS CloudHSM to perform encryption operations from the application.

    Why this is correct

    CloudHSM provides a dedicated HSM, offloading encryption.

  • ✗

    Use AWS KMS with a customer-managed key to encrypt the data in the application.

    Why it's wrong here

    KMS is software-based; does not provide a dedicated HSM.

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.