SCS-C02 Data Protection Practice Question
A company wants to ensure that data stored in Amazon EBS volumes is encrypted at rest. What is the easiest way to achieve this?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable EBS encryption by default in the AWS Region
Enabling EBS encryption by default in the AWS Region automatically encrypts all new EBS volumes and snapshots with no additional effort. Option A is incorrect: KMS key rotation does not enable encryption; it rotates the key used for encryption. Option B is incorrect: while you can encrypt individual volumes after creation, the easiest method is to enable default encryption. Option D is incorrect: application-level encryption is not needed for EBS volumes and is more complex to implement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use AWS KMS to rotate the EBS encryption key
Why it's wrong here
Rotating the AWS KMS key, even with automatic annual rotation, only replaces the backing CMK material used to decrypt newly created data keys; it has no effect on the encryption state of EBS volumes that already exist. An unencrypted volume remains unencrypted regardless of KMS key rotation because encryption is an attribute assigned when the volume or snapshot is created. KMS rotation also does not cause any new encrypted volumes or snapshots to be provisioned, so it cannot satisfy the requirement.
- ✗
Use a script to encrypt each volume after creation
Why it's wrong here
Writing a script to encrypt volumes after creation is not the native or easiest approach because EBS encryption cannot be enabled in place. You would have to stop the instance, take a snapshot (or copy it to an encrypted snapshot), create a new encrypted volume or instance, and then migrate the data, which is disruptive and error-prone. It also does not enforce encryption for volumes that will be created later, unless you tie the script into your provisioning pipeline, making it a manual safeguard rather than a default rule.
- ✓
Enable EBS encryption by default in the AWS Region
Why this is correct
Enabling EBS encryption by default in the Region is the easiest and most reliable method because it instructs the EC2 service to always encrypt newly created volumes and snapshots at the storage layer. When enabled, every new EBS volume and every new snapshot is encrypted with your default AWS KMS key (either the aws/ebs managed key or a customer-managed key you designate). This setting applies to all volumes created in that Region, including root volumes launched from unencrypted AMIs, without requiring you to modify applications or remember to check an encryption box.
- ✗
Use application-level encryption
Why it's wrong here
Application-level encryption protects data before it writes to disk, but it is independent of EBS and requires developers to explicitly encrypt fields or objects in code, which is far more complex than a storage-layer default. It also creates key-management overhead and affects queryability and performance, whereas EBS encryption is transparent to the application. Because the question asks for the easiest way to ensure EBS data is encrypted, this option is too heavy and indirect.
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.