Courseiva
Data Protection →mediumMultiple Choice

SCS-C02 Data Protection Practice Question

A company uses AWS KMS to encrypt data in Amazon RDS. They need to ensure that the key material is automatically rotated every year. Which key type should they use?

⚠ Common exam trap

Candidates often confuse 'AWS managed key' with 'customer managed key' because both can be rotated, but the question tests whether you know that AWS managed keys are the default, automatically rotated keys used by services like RDS, and that customer managed keys require manual configuration for rotation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS managed key

AWS managed keys (D) are automatically rotated every year by AWS without any action required from the customer. For Amazon RDS encryption using AWS KMS, the default key (aws/rds) is an AWS managed key that supports automatic annual rotation, meeting the requirement exactly. Customer managed keys (B) also support automatic rotation, but the question specifies 'every year' and AWS managed keys are the simplest choice that satisfies this, as they are automatically rotated annually by default.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Custom key store

    Why it's wrong here

    A custom key store is backed by a CloudHSM cluster, and while it gives you sole control over the HSM, KMS does not perform automatic rotation for keys in a custom key store. Because RDS encryption would inherit that behavior, a custom key store would not satisfy a requirement for automatic key rotation. Therefore it cannot be the correct choice here.

  • ✗

    Customer managed key

    Why it's wrong here

    A customer managed key is created and controlled by your account, and KMS only rotates it automatically if you explicitly enable automatic rotation; the default is no automatic rotation. For RDS encryption, you could choose this key type, but the question asks which key type rotates automatically by default, so this wrong answer conflates an opt-in capability with automatic behavior.

  • ✗

    AWS owned key

    Why it's wrong here

    AWS owned keys are the KMS key type used internally by AWS services to encrypt data in shared service-side infrastructure; they are not used to encrypt customer-controlled resources like RDS instances. RDS always uses either a customer managed key or an AWS managed key selected on the KMS console, never an AWS owned key, so this option is factually incorrect for the scenario.

  • ✓

    AWS managed key

    Why this is correct

    AWS managed keys are KMS keys created automatically when a service first needs encryption, and Amazon RDS's AWS managed key (alias aws/rds) has automatic rotation enabled by default, rotating the backing key material every year. Because the key is managed in the AWS account's service space, you cannot disable rotation, which neatly matches a requirement for guaranteed automatic rotation without any administrative action.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.