SCS-C02 Data Protection Practice Question
A company wants to protect data at rest for an Amazon RDS for PostgreSQL database. Which AWS service should be used to manage the encryption keys?
⚠ Common exam trap
Test-takers frequently confuse AWS Secrets Manager (which manages secrets like passwords) with KMS (which manages encryption keys), leading them to select Secrets Manager for key management instead of the correct service for RDS encryption at rest.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Key Management Service (KMS)
Amazon RDS for PostgreSQL integrates with AWS Key Management Service (KMS) to enable encryption at rest. When you enable encryption for an RDS DB instance, KMS manages the customer master keys (CMKs) that encrypt the data keys used by the storage layer. This is the standard, fully managed key management service for RDS encryption, supporting automatic key rotation and fine-grained access control.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS CloudHSM
Why it's wrong here
AWS CloudHSM provides dedicated single-tenant hardware security modules where you control the HSMs and manage your own keys. However, Amazon RDS does not use CloudHSM as its default or supported encryption mechanism for data at rest; RDS encryption must use keys managed through AWS KMS. While CloudHSM is a valid option for other high-control encryption scenarios, it cannot be used to encrypt RDS storage natively, so this answer is incorrect.
- ✓
AWS Key Management Service (KMS)
Why this is correct
AWS Key Management Service (KMS) is the correct service for encrypting Amazon RDS data at rest. When you enable RDS encryption, you select a KMS customer master key (CMK) — either the AWS-managed key (aws/rds) or a customer-managed CMK — which encrypts the underlying storage, automated backups, snapshots, and read replicas. KMS also provides fine-grained access control and AWS CloudTrail auditing for every key use, making it the native integration point for RDS storage encryption.
- ✗
AWS Certificate Manager (ACM)
Why it's wrong here
AWS Certificate Manager (ACM) issues and manages public or private TLS/SSL certificates that are used to encrypt data in transit, such as connections between your application and an RDS instance. While ACM can provision certificates that RDS uses for TLS connections to the database, it does not perform or manage encryption of the physical data files on disk. Because the question specifically asks about protecting data at rest, ACM's transport-layer role is unrelated, making it an incorrect choice.
- ✗
AWS Secrets Manager
Why it's wrong here
AWS Secrets Manager is designed to centrally store and rotate database credentials, API keys, and other secrets, not to manage the underlying encryption keys that decrypt your RDS data volumes. Even though RDS encryption involves managing passwords for access, Secrets Manager does not create or control the KMS CMKs that RDS uses for encrypting data at rest. Therefore, while Secrets Manager is a security-related service, it does not satisfy the data-at-rest encryption key requirement, so it is incorrect.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.