Courseiva
Data Protection →hardMultiple Choice

SCS-C02 Data Protection Practice Question

A company uses AWS CloudHSM to store encryption keys for a custom database encryption application. The application runs on Amazon EC2 instances and uses the PKCS#11 library to communicate with the HSM. Recently, the application started failing with 'CKR_SESSION_HANDLE_INVALID' errors. Which of the following is the most likely cause?

⚠ Common exam trap

The trap is confusing network or authentication errors with PKCS#11 session errors — candidates may pick security group or certificate issues, but the specific error code CKR_SESSION_HANDLE_INVALID points directly to session management on the HSM.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The application is not closing sessions properly, causing the HSM to reach the maximum number of open sessions

CKR_SESSION_HANDLE_INVALID is a PKCS#11 error indicating that the session handle used by the application is no longer valid. This typically occurs when the application opens sessions but fails to close them, eventually exhausting the HSM's maximum session limit. Once the limit is reached, new session requests fail or existing handles become invalid. Proper session management (closing sessions after use) is required to avoid this error.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The client certificate used for mutual TLS authentication has expired

    Why it's wrong here

    An expired client certificate breaks the mutual TLS handshake between the EC2 instance's CloudHSM client and the HSM appliance before any PKCS#11 session exists. The SDK reports cryptographic identity or connection failures such as CKR_NETWORK_ERROR or CKR_GENERAL_ERROR at C_OpenSession, but it cannot produce CKR_SESSION_HANDLE_INVALID because no session handle was ever created. Authentication, not session lifecycle management, is the failure point.

  • ✗

    The security group for the HSM does not allow inbound traffic from the EC2 instance

    Why it's wrong here

    If the security group attached to the HSM network interfaces blocks inbound traffic from the EC2 instance, the TCP connection to port 2223 will time out or be reset during C_OpenSession. This produces transport-level errors like CKR_NETWORK_ERROR or CKR_DEVICE_ERROR before a session handle is allocated. The HSM never sees the session request, so session exhaustion and invalid session handles cannot be the cause; the error appears immediately regardless of prior session usage.

  • ✓

    The application is not closing sessions properly, causing the HSM to reach the maximum number of open sessions

    Why this is correct

    PKCS#11 sessions on a CloudHSM are finite, and each session handle is valid only until C_CloseSession or C_Finalize is called. An application that fails to close sessions leaks them, and once the HSM client's session limit is reached, any handle retained from an evicted or expired session returns CKR_SESSION_HANDLE_INVALID on subsequent operations. This is the correct explanation: the root cause is session lifecycle mismanagement, not network or identity configuration, and the fix is to use try-with-resources or a session pool that guarantees C_CloseSession in all code paths.

  • ✗

    The HSM's firmware version is incompatible with the PKCS#11 library

    Why it's wrong here

    The PKCS#11 library and HSM firmware must be mutually compatible because the library negotiates function lists and capability details with the firmware during initialization. A version mismatch typically causes C_GetInfo, C_Initialize, or C_GetFunctionList to fail with CKR_DEVICE_ERROR or CKR_CRYPTOKI_NOT_INITIALIZED before any session is created. Since no valid session handle can exist at that stage, the symptom would be an immediate startup failure, not an invalid-session-handle error during normal operations.

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.