Courseiva
Data Protection →hardMultiple Choice

SCS-C02 Data Protection Practice Question

A company uses AWS CloudHSM to generate and store encryption keys for a custom application. The security team needs to ensure high availability and durability of the keys. Which architecture should be recommended?

⚠ Common exam trap

SCS-C02 often tests the misconception that CloudHSM automatically replicates across regions, but it does not; candidates may also think that a single HSM is sufficient for high availability.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deploy a CloudHSM cluster with at least two HSMs in different Availability Zones

Deploying a CloudHSM cluster with at least two HSMs in different Availability Zones provides high availability and durability. CloudHSM automatically synchronizes keys across HSMs in the cluster, so if one HSM fails, the others continue to provide access to the keys.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use AWS KMS instead of CloudHSM for better durability

    Why it's wrong here

    KMS is a managed service that provides durable, multi-AZ key storage, but CloudHSM is not inherently less durable; it can achieve the same availability by deploying a cluster across Availability Zones. The real benefit of CloudHSM is single-tenant hardware with FIPS 140-2 Level 3 validation, allowing you to control the HSM and manage keys via PKCS#11, JCE, or OpenSSL APIs. Choosing KMS would change your key-management architecture and reduce your direct control over the underlying HSM, not improve durability. Therefore, 'use KMS for better durability' is not a valid option.

  • ✗

    Deploy a single CloudHSM instance in one Availability Zone

    Why it's wrong here

    A single HSM instance deployed in one Availability Zone creates a single point of failure because CloudHSM hardware must be available for cryptographic operations, and a power outage, network partition, or device failure in that AZ makes the HSM unreachable. Cluster clients would fail to connect, and while the keys still exist on the device, they are not automatically copied to any other HSM. AWS recommends a minimum of two HSMs in different Availability Zones so the cluster can fail over transparently; one HSM gives no redundancy. Thus, this does not meet high-availability requirements.

  • ✗

    Deploy CloudHSM in two AWS Regions with automatic replication

    Why it's wrong here

    Deploying CloudHSM in two AWS Regions cannot rely on automatic cross-region replication because CloudHSM cluster synchronization only replicates data among HSMs in the same cluster and same Region. To move keys between Regions, you must create an HSM backup in the source Region and restore it into a cluster in the target Region, using the CloudHSM CLI or console; this is a manual backup/restore process, not automatic replication. Additionally, a single HSM in each Region would still lack high availability within each region. Therefore, the step is incorrect because automatic cross-region replication is not a CloudHSM feature.

  • ✓

    Deploy a CloudHSM cluster with at least two HSMs in different Availability Zones

    Why this is correct

    Creating a CloudHSM cluster with at least two HSMs in different Availability Zones ensures that if one HSM or AZ becomes unavailable, the other HSM can continue serving cryptographic operations. CloudHSM automatically synchronizes users, keys, and policies across all HSMs in the cluster, so the remaining HSM has the same key material. This architecture provides redundancy, high availability, and aligns with AWS recommended best practices for CloudHSM. Hence, it is the correct answer for improving durability/availability while keeping the HSM-based control.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.