Courseiva
Data Protection →hardMultiple Choice

SCS-C02 Data Protection Practice Question

A company uses Amazon EBS volumes for EC2 instances. Security policy requires that all EBS volumes be encrypted at rest. The company already has a default KMS key for EBS encryption. However, some new volumes are created without encryption. What is the most efficient way to enforce encryption for all new EBS volumes?

⚠ Common exam trap

SCS-C02 often tests whether candidates choose detective/corrective controls (Config + Lambda, CloudTrail alerts) over the native preventive control (EBS encryption by default), which is simpler and more efficient.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable EBS encryption by default in the EC2 console or via the API

Enabling EBS encryption by default in the EC2 console or via the API (EnableEbsEncryptionByDefault) ensures that every new EBS volume created in the region is automatically encrypted with the specified KMS key, without requiring any per-volume action or custom tooling. This is the most efficient, native enforcement mechanism because it operates at the account/region level and applies to all volume creation paths, including those from AMIs, snapshots, and instance launches.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use AWS CloudTrail to monitor volume creation and send alerts

    Why it's wrong here

    AWS CloudTrail records API activity like RunInstances and CreateVolume, and you can configure CloudWatch Events to send alerts when unencrypted volumes are created. However, this is purely detective and reactive: the alert fires after the fact, does not block the operation, and leaves the unencrypted volume in place until you manually intervene, so it cannot be used as a prevention mechanism.

  • ✗

    Create an AWS Config rule to detect unencrypted volumes and trigger a Lambda function to encrypt them

    Why it's wrong here

    An AWS Config rule can detect volumes that are not encrypted and invoke a Lambda function, but the remediation is non-trivial and eventual. To encrypt an existing volume, Lambda must create a new encrypted volume from a snapshot and then swap it into the EC2 instance, which requires stopping the instance, detaching volumes, and re-attaching—causing downtime. This is reactive, adds operational complexity, and does not prevent the initial creation of unencrypted volumes, so it falls short of enforcing encryption by default.

  • ✗

    Use a custom AMI that enforces encryption

    Why it's wrong here

    A custom AMI with encrypted snapshots ensures that instances launched from that AMI get encrypted root volumes, but it does not enforce encryption for all EBS volumes. Users can still create unencrypted volumes, attach additional unencrypted volumes to instances, or create volumes from unencrypted snapshots outside the AMI's scope, so this approach is not a comprehensive preventive control and cannot enforce encryption across the account.

  • ✓

    Enable EBS encryption by default in the EC2 console or via the API

    Why this is correct

    Enable EBS encryption by default at the account or region level, either through the EC2 console or the API (EnableEbsEncryptionByDefault). This setting automatically encrypts all newly created volumes, snapshots, and volumes created from those snapshots, using either the default AWS-managed key or a custom KMS key you specify. Because it is enforced at creation time, it is a preventive control that eliminates the risk of accidentally leaving new volumes unencrypted, which is exactly what the security requirement demands.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.