SCS-C02 Data Protection Practice Question
A company uses AWS CloudHSM to generate and store encryption keys for a custom application. The security team needs to ensure high availability and durability of the keys. Which architecture should be recommended?
⚠ Common exam trap
SCS-C02 often tests the misconception that CloudHSM automatically replicates across regions, but it does not; candidates may also think that a single HSM is sufficient for high availability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy a CloudHSM cluster with at least two HSMs in different Availability Zones
Deploying a CloudHSM cluster with at least two HSMs in different Availability Zones provides high availability and durability. CloudHSM automatically synchronizes keys across HSMs in the cluster, so if one HSM fails, the others continue to provide access to the keys.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use AWS KMS instead of CloudHSM for better durability
Why it's wrong here
KMS is a managed service that provides durable, multi-AZ key storage, but CloudHSM is not inherently less durable; it can achieve the same availability by deploying a cluster across Availability Zones. The real benefit of CloudHSM is single-tenant hardware with FIPS 140-2 Level 3 validation, allowing you to control the HSM and manage keys via PKCS#11, JCE, or OpenSSL APIs. Choosing KMS would change your key-management architecture and reduce your direct control over the underlying HSM, not improve durability. Therefore, 'use KMS for better durability' is not a valid option.
- ✗
Deploy a single CloudHSM instance in one Availability Zone
Why it's wrong here
A single HSM instance deployed in one Availability Zone creates a single point of failure because CloudHSM hardware must be available for cryptographic operations, and a power outage, network partition, or device failure in that AZ makes the HSM unreachable. Cluster clients would fail to connect, and while the keys still exist on the device, they are not automatically copied to any other HSM. AWS recommends a minimum of two HSMs in different Availability Zones so the cluster can fail over transparently; one HSM gives no redundancy. Thus, this does not meet high-availability requirements.
- ✗
Deploy CloudHSM in two AWS Regions with automatic replication
Why it's wrong here
Deploying CloudHSM in two AWS Regions cannot rely on automatic cross-region replication because CloudHSM cluster synchronization only replicates data among HSMs in the same cluster and same Region. To move keys between Regions, you must create an HSM backup in the source Region and restore it into a cluster in the target Region, using the CloudHSM CLI or console; this is a manual backup/restore process, not automatic replication. Additionally, a single HSM in each Region would still lack high availability within each region. Therefore, the step is incorrect because automatic cross-region replication is not a CloudHSM feature.
- ✓
Deploy a CloudHSM cluster with at least two HSMs in different Availability Zones
Why this is correct
Creating a CloudHSM cluster with at least two HSMs in different Availability Zones ensures that if one HSM or AZ becomes unavailable, the other HSM can continue serving cryptographic operations. CloudHSM automatically synchronizes users, keys, and policies across all HSMs in the cluster, so the remaining HSM has the same key material. This architecture provides redundancy, high availability, and aligns with AWS recommended best practices for CloudHSM. Hence, it is the correct answer for improving durability/availability while keeping the HSM-based control.
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.