Courseiva
Data Protection →mediumMultiple Choice

SCS-C02 Data Protection Practice Question

A company uses AWS KMS with a custom key store backed by AWS CloudHSM. The security team wants to ensure that the key material never leaves the HSM and that all cryptographic operations are performed within the HSM. Which of the following actions should the team take?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create the KMS key in a custom key store and set the key usage to 'ENCRYPT_DECRYPT'.

To ensure key material never leaves the HSM and cryptographic operations are performed within the HSM, the team should create the KMS key in a custom key store (backed by CloudHSM) and set the key usage to ENCRYPT_DECRYPT. This ensures that the key material is stored and used only within the HSM. Option A is incorrect because asymmetric keys with SIGN_VERIFY usage are not the standard for encryption/decryption, and the key material could potentially be exported if the HSM allows. Option B is incorrect because the 'Prevent key material export' option is not available in KMS; custom key stores inherently prevent export. Option C is incorrect because the default key store uses software-based keys, not HSM hardware. Therefore, Option D is the correct answer.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create the KMS key as an asymmetric key in a custom key store and set the key usage to 'SIGN_VERIFY'.

    Why it's wrong here

    An asymmetric KMS key with SIGN_VERIFY is cryptographically restricted and can never be used for encryption or decryption of data. Even in a CloudHSM-backed custom key store, the key usage parameter is immutable after creation and only permits digital signature generation and verification. Therefore, this option fails the requirement if the intended operation is to encrypt data; the KMS key would need a key usage of ENCRYPT_DECRYPT instead.

  • ✗

    Enable the 'Prevent key material export' option in the KMS key policy.

    Why it's wrong here

    AWS KMS does not have a configurable property called 'Prevent key material export' in a key policy, and KMS key policies cannot alter how key material is stored or exposed. All KMS key material is non-exportable as a service feature, and in a custom key store the CloudHSM hardware enforces that the unencrypted private key bytes never leave the HSM. Adding such a statement to a key policy would be invalid and would not satisfy the requirement.

  • ✗

    Create the KMS key as a symmetric key in the default key store.

    Why it's wrong here

    A symmetric KMS key in the default key store is protected by AWS KMS's own FIPS-validated HSMs, but these HSMs are AWS-managed and not dedicated to the customer's CloudHSM cluster. The default key store therefore cannot provide the explicit customer-controlled hardware boundary that a custom key store provides, and key material may be cached in service memory during cryptographic operations. This does not meet the requirement for key material to reside exclusively in a customer-managed HSM.

  • ✓

    Create the KMS key in a custom key store and set the key usage to 'ENCRYPT_DECRYPT'.

    Why this is correct

    Creating a symmetric KMS key in a CloudHSM-backed custom key store with key usage set to ENCRYPT_DECRYPT ensures that the key material is generated and used only inside the customer's dedicated HSM cluster. The HSM performs all encryption and decryption operations for that key, and the unencrypted key material never leaves the HSM or becomes visible to AWS KMS service processes. This satisfies both the HSM residency requirement and the need for a general-purpose data encryption key.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.