SCS-C02 Data Protection Practice Question
A company uses AWS CloudHSM to generate and store encryption keys for a custom database. The security team needs to back up the keys to another AWS Region for disaster recovery. What is the most secure and efficient way to achieve this?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a backup of the source CloudHSM cluster and copy the backup to the destination Region.
AWS CloudHSM allows you to create a backup of a cluster and copy that backup to another region using the AWS CLI or console. This is the most secure method as it avoids exporting keys in plaintext. Option B is incorrect because CloudHSM does not support exporting keys directly; you must use backups. Option C is incorrect because CloudHSM does not have a cross-region replication feature for clusters. Option D is incorrect because copying keys via an on-premises HSM is unnecessary and less secure than using CloudHSM's built-in backup copy functionality.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a backup of the source CloudHSM cluster and copy the backup to the destination Region.
Why this is correct
AWS CloudHSM supports taking point-in-time backups of an entire cluster, and those backups can be copied to other regions using the CopyBackupToRegion API or the console. After copying, you restore the backup in the destination region to create a new cluster that contains all original keys, HSMs, and settings. This preserves FIPS 140-2 validated protection because key material never leaves the HSM boundary, and it is the officially supported method for cross-region disaster recovery.
- ✗
Export the keys from the source CloudHSM cluster and import them into a destination cluster in the other Region.
Why it's wrong here
Although CloudHSM APIs and key_mgmt_util include key wrapping and export functions, exporting key material to a destination cluster outside the HSM boundary is not supported as a disaster recovery strategy. For an export, keys must be marked 'exportable' during creation, and the wrapping process exposes the key to the client application, bypassing the hardware security guarantees that CloudHSM provides. In contrast, a backup copy keeps the keys inside encrypted HSM images, so AWS's recommended and secure path is to copy and restore a cluster backup rather than exporting and importing keys.
- ✗
Enable cross-Region replication on the CloudHSM cluster.
Why it's wrong here
A CloudHSM cluster is bound to a single AWS Region and VPC; it provides high availability by running multiple HSM instances that are synchronised within that cluster only. AWS does not offer a service-managed cross-Region replication feature for CloudHSM clusters, unlike for some other AWS data stores. To achieve cross-region redundancy, you must restore a cluster from a backup that you copy to the target region; replication across regions is not a configurable option.
- ✗
Use the key_mgmt_util command-line tool to copy the keys to an on-premises HSM, then upload to the destination Region.
Why it's wrong here
The key_mgmt_util tool only operates on the HSMs in the cluster to which you're currently connected; it cannot copy keys to an external on-premises HSM for later upload. Attempting to exfiltrate key material to an on-premises HSM and then re-import it to another region would involve extracting the keys in a wrapped or even plaintext form, exposing them to the network and host, in violation of the FIPS 140-2 security model. The only supported workflow for moving keys across regions is to copy the CloudHSM cluster backup to the destination region and restore it there.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.