SCS-C02 Data Protection Practice Question
A company uses AWS CloudHSM to store encryption keys. The security team wants to ensure that keys stored in CloudHSM are backed up and can be restored in another AWS Region. What is the BEST approach?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Export the security domain from the source cluster and import it into a new cluster in the target region
AWS CloudHSM allows you to export the security domain from a source cluster, which contains the cryptographic material needed to back up and restore keys. You can then create a new CloudHSM cluster in the target region and import the security domain to restore the keys. Option A is incorrect because CloudHSM does not support automatic cross-region replication. Option B is incorrect because HSM user credentials alone do not contain the key material; they are used for authentication, not backup. Option C is incorrect because AWS Backup does not integrate with CloudHSM to back up the cluster's keys.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable automatic cross-region replication on the CloudHSM cluster
Why it's wrong here
CloudHSM clusters are region-scoped and do not provide any managed automatic cross-region replication feature. Cluster replication in CloudHSM only adds HSMs across Availability Zones within the same Region for high availability, not for disaster recovery in another Region. To recover keys elsewhere, you must copy a CloudHSM backup and restore it into a new cluster initialized with the original security domain; there is no automatic replication toggle that accomplishes this.
- ✗
Copy the HSM user credentials and use them in the new region
Why it's wrong here
Copying HSM user credentials is irrelevant to key recovery because credentials such as CU or CI passwords only authenticate human users or the HSM appliance; they contain no key material. CloudHSM keys are non-exportable and are cryptographically wrapped by the cluster's security domain, not by user passwords. Without the security domain generated at cluster initialization, a new cluster in another region cannot decrypt the HSM backups that contain the original keys, so credentials alone cannot restore anything.
- ✗
Use AWS Backup to back up the CloudHSM cluster and restore in another region
Why it's wrong here
AWS Backup is a centralized backup service, but CloudHSM clusters are not a supported resource type in AWS Backup, so this option is technically impossible. CloudHSM has its own native backup and restore mechanism through the CloudHSM API and console, and cross-region recovery requires copying an HSM backup to the destination region and restoring it into a cluster configured with the correct security domain. AWS Backup cannot capture or restore CloudHSM key material because it has no integration with the HSM hardware or its security domain.
- ✓
Export the security domain from the source cluster and import it into a new cluster in the target region
Why this is correct
The security domain is the encrypted root-of-trust material generated when a CloudHSM cluster is initialized, and it is required to decrypt cluster backups and recover the keys stored in the HSM. By exporting the security domain from the source cluster and importing or supplying it during the initialization of a new cluster in the target region, you give the new cluster the ability to unlock the restored backup and retrieve the original key material. This is the correct disaster-recovery action, and it must be paired with copying and restoring a CloudHSM backup to that region.
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.