Courseiva
Data Protection →mediumMultiple Choice

SCS-C02 Data Protection Practice Question

A company uses AWS KMS to manage encryption keys for sensitive data stored in S3. The security team wants to ensure that keys are rotated automatically every year. What should they do?

⚠ Common exam trap

SCS-C02 often tests the distinction between customer managed keys (configurable rotation) and AWS managed keys (automatic but not controllable) — candidates who pick the AWS managed key option miss the governance requirement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable automatic key rotation on a customer managed key.

Automatic key rotation is a native feature of AWS KMS customer managed keys (CMKs). Enabling it causes KMS to generate new backing key material every year (or a custom period of 90-2560 days) while retaining the same key ID, so existing ciphertext remains decryptable without re-encryption. This satisfies the 'rotate automatically every year' requirement with no manual intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable automatic key rotation on a customer managed key.

    Why this is correct

    Enabling automatic key rotation on a customer managed key lets AWS KMS rotate the backing key material annually without changing the key ID or ARN, so existing ciphertext and applications continue working. This satisfies the yearly rotation requirement.

  • ✗

    Use a custom key store and rotate keys manually.

    Why it's wrong here

    A custom key store still requires the team to rotate keys manually, so it cannot deliver the automatic yearly rotation the security team wants. Custom key stores suit scenarios needing keys backed by CloudHSM while retaining KMS API integration, not automated rotation schedules.

  • ✗

    Use a CloudHSM to store keys and rotate them manually.

    Why it's wrong here

    CloudHSM gives no automatic annual rotation and requires manual key rotation, failing the stated requirement. It is the right choice when regulatory mandates demand single-tenant hardware security modules with exclusive customer control over key material, not when scheduled rotation is the goal.

  • ✗

    Use an AWS managed key, which rotates automatically every year.

    Why it's wrong here

    AWS managed keys rotate automatically every three years, not yearly, and their policies cannot be customised, so they fail the annual requirement. They are the correct choice when a workload needs basic encryption with no key administration and a three-year rotation cadence is acceptable.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.