SCS-C02 Data Protection Practice Question
A company wants to ensure that data at rest in Amazon EBS volumes is encrypted. What is the simplest way to achieve this?
⚠ Common exam trap
SCS-C02 often tests the simplest way to enforce EBS encryption, and candidates may choose manual encryption or custom KMS keys, overlooking the account-level default encryption setting.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable EBS encryption by default in the AWS account.
The simplest way to ensure that data at rest in Amazon EBS volumes is encrypted is to enable EBS encryption by default in the AWS account. This setting automatically encrypts all new EBS volumes created in the account, using the default KMS key for EBS encryption. It eliminates the need to manually encrypt each volume or attach custom KMS keys. Other methods are more manual and do not provide the same level of automation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable EBS encryption by default in the AWS account.
Why this is correct
Enabling EBS encryption by default at the account or Region level is the simplest, AWS-native way to enforce encryption for all new EBS volumes. No per-volume configuration is required: every newly created volume and any snapshot copied from it is automatically encrypted with the account's default KMS key (AWS-managed or customer-managed). This setting does not retroactively encrypt existing unencrypted volumes, but it ensures all future data-at-rest is protected across the account.
- ✗
Use AWS KMS to create a custom key and attach it to each volume.
Why it's wrong here
Creating a custom KMS key and attaching it per volume requires manual key management and per-volume configuration, whereas the simplest method is to enable EBS encryption by default at the account or region level, which automatically encrypts all new volumes without any per-volume action. This option is tempting because custom KMS keys offer granular control and are correct when you need to enforce specific encryption policies or separate key administration for different volumes.
- ✗
Encrypt each volume manually using the AWS Management Console.
Why it's wrong here
Manually encrypting each EBS volume through the Management Console requires administrators to remember to select encryption at volume creation, which is error-prone and impossible to enforce consistently. Existing unencrypted volumes cannot be encrypted in place through the console; they must be stopped, snapshotted, and restored as encrypted copies. This ad-hoc approach does not establish a default policy and therefore cannot guarantee that all current and future volumes are encrypted.
- ✗
Use an operating system-level encryption tool like LUKS.
Why it's wrong here
An OS-level tool such as LUKS encrypts data inside the guest OS, but it relies on the customer to manage keys, LUKS headers, and boot processes on every instance. It does not integrate with AWS KMS or CloudTrail for centralized auditing, and the encryption is not recorded or enforced at the EBS service level. This is a valid defense-in-depth measure, but it is far more operational overhead than simply enabling EBS encryption by default.
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.