SCS-C02 Data Protection Practice Question
A company uses AWS KMS to manage encryption keys for sensitive data stored in S3. The security team wants to ensure that keys are rotated automatically every year. What should they do?
⚠ Common exam trap
SCS-C02 often tests the distinction between customer managed keys (configurable rotation) and AWS managed keys (automatic but not controllable) — candidates who pick the AWS managed key option miss the governance requirement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable automatic key rotation on a customer managed key.
Automatic key rotation is a native feature of AWS KMS customer managed keys (CMKs). Enabling it causes KMS to generate new backing key material every year (or a custom period of 90-2560 days) while retaining the same key ID, so existing ciphertext remains decryptable without re-encryption. This satisfies the 'rotate automatically every year' requirement with no manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable automatic key rotation on a customer managed key.
Why this is correct
Enabling automatic key rotation on a customer managed key lets AWS KMS rotate the backing key material annually without changing the key ID or ARN, so existing ciphertext and applications continue working. This satisfies the yearly rotation requirement.
- ✗
Use a custom key store and rotate keys manually.
Why it's wrong here
A custom key store still requires the team to rotate keys manually, so it cannot deliver the automatic yearly rotation the security team wants. Custom key stores suit scenarios needing keys backed by CloudHSM while retaining KMS API integration, not automated rotation schedules.
- ✗
Use a CloudHSM to store keys and rotate them manually.
Why it's wrong here
CloudHSM gives no automatic annual rotation and requires manual key rotation, failing the stated requirement. It is the right choice when regulatory mandates demand single-tenant hardware security modules with exclusive customer control over key material, not when scheduled rotation is the goal.
- ✗
Use an AWS managed key, which rotates automatically every year.
Why it's wrong here
AWS managed keys rotate automatically every three years, not yearly, and their policies cannot be customised, so they fail the annual requirement. They are the correct choice when a workload needs basic encryption with no key administration and a three-year rotation cadence is acceptable.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.