Courseiva
Data Protection →hardMultiple Choice

SCS-C02 Data Protection Practice Question

A company uses AWS CloudHSM to generate and store encryption keys for a custom application. The application runs on Amazon EC2 instances and uses the PKCS#11 interface to interact with the HSM. The security team recently discovered that a former employee may have obtained a copy of the cryptographic materials from the HSM. What should the security team do to minimize the impact?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Delete the CloudHSM backup from the backup service. Then rotate all keys that were stored in the HSM.

Deleting the CloudHSM backup prevents the former employee from restoring the HSM's contents from a backup. Rotating all keys ensures that any keys the employee may have copied are no longer valid for encrypting/decrypting data, minimizing the impact of the exposure. Option A is incorrect because AWS KMS cannot manage keys stored in CloudHSM. Option C is incorrect because changing passwords does not invalidate cryptographic material that has already been copied. Option D is incorrect because deleting the HSM cluster alone does not delete the backup, and restoring from an old backup may reintroduce the compromised keys.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use AWS KMS to create a new key and re-encrypt all data. Then revoke the old key.

    Why it's wrong here

    AWS KMS is a separate key management service that cannot revoke or invalidate key material stored in an AWS CloudHSM cluster; the application directly uses CloudHSM, so a KMS key revocation has no effect on the compromised HSM-backed key. Even if data were re-encrypted under a new KMS key, any data still encrypted with the old HSM key would remain exposed, and the copied backup is not remediated. Thus, this option does not address the actual compromise and is ineffective.

  • ✓

    Delete the CloudHSM backup from the backup service. Then rotate all keys that were stored in the HSM.

    Why this is correct

    Deleting the CloudHSM backup from the backup service ensures that the copied encrypted key material that was exfiltrated cannot be restored to a new or existing HSM, eliminating the attacker's ability to recover the keys. After that, rotating every key that was stored in the HSM—generating new keys and re-encrypting data with them—renders any previously copied key material useless because the data is now protected by fresh keys. This two-step approach directly addresses both ways the compromise can be exploited: backup restoration and continued use of the old key material.

  • ✗

    Change the HSM administrator password and the crypto user passwords.

    Why it's wrong here

    Changing the HSM administrator and crypto user passwords only alters the credentials used to authenticate to the HSM; it does not modify or invalidate the cryptographic key material that was copied from the backup. The copied key material remains valid and usable in any HSM that accepts it, because CloudHSM keys are protected by the HSM's master keys, not by the cluster's user passwords. Therefore, password rotation leaves the compromised keys fully functional and the data still exposed.

  • ✗

    Delete the HSM cluster and create a new one. Restore the backup from a known good time.

    Why it's wrong here

    Deleting the HSM cluster and creating a new one does not delete the backups stored in the backup service; those backups are independent of the cluster and can be restored to any HSM by someone with access. Restoring from a 'known good time' is flawed because the backup that the employee copied may contain the same key material, and if it is from before the compromise, it still contains the keys that are now compromised. The correct action is to delete the backup and rotate the keys, not to rebuild the cluster from backups that may still include the exposed key material.

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.