Courseiva
Data Protection →easyMultiple Choice

SCS-C02 Data Protection Practice Question

A company uses Amazon S3 to store confidential documents. The security team wants to ensure that all objects are encrypted at rest using server-side encryption with AES-256. Which S3 encryption option should be used?

⚠ Common exam trap

SCS-C02 often tests the confusion between 'AES-256' as an algorithm and the key-management model, tempting candidates to select SSE-KMS for stronger-sounding control when the requirement only specifies AES-256 at rest.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SSE-S3

SSE-S3 applies server-side encryption with AES-256 using keys fully managed by Amazon S3, meeting the requirement for AES-256 encryption at rest without customer key management overhead. It is the default and simplest S3-managed encryption option, automatically encrypting every object with strong AES-256 and requiring no additional configuration or key infrastructure. This directly satisfies the stated requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    SSE-C

    Why it's wrong here

    SSE-C (server-side encryption with customer-provided keys) uses an AES-256 key that you own and supply with each S3 request. Amazon S3 performs the encryption at the server side, but it does not store your key; you must maintain and send the same key on every GET, PUT, or HEAD operation. This is wrong here because the keys are not managed by S3 and the encryption lifecycle is entirely dependent on the customer's key management.

  • ✗

    SSE-KMS

    Why it's wrong here

    SSE-KMS (server-side encryption with AWS Key Management Service) encrypts objects using envelope encryption: S3 generates a data key and encrypts it with a customer master key (CMK) stored in AWS KMS, while the object data is encrypted with AES-256. This provides separate IAM permissions, audit trails, and customer-managed key rotation, but it is not the simple, pure 'S3-managed AES-256' option. It is wrong for this scenario because the encryption is performed using KMS-managed keys and incurs additional KMS API costs and permissions.

  • ✓

    SSE-S3

    Why this is correct

    SSE-S3 (server-side encryption with Amazon S3 managed keys) is the correct option because it uses strong AES-256 encryption with keys that are managed entirely by Amazon S3. Each object is encrypted with a unique data key, and the data key is wrapped by a regular rotating S3-managed key. This gives S3 the responsibility for encrypting confidential documents with no additional cost, no key rotation overhead, and no need for the customer to supply or manage keys.

  • ✗

    Client-side encryption

    Why it's wrong here

    Client-side encryption is performed by the customer before the data is ever sent to Amazon S3, meaning the plaintext and the encryption keys never leave the client environment. This approach gives the customer full control, but it is not a server-side encryption feature of S3 and requires SDKs or external libraries to manage key generation, encryption logic, and key storage. It is wrong in this context because the question is about an S3-managed encryption option, not encrypting data outside of S3.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.